Hi,
I am trying to enable file monitoring using a Splunk universal forwarder, but not able to see any events generated. I've followed other articles for this issue, but in vain.
As a test, I created a text file on the desktop and added to monitoring under inputs.conf
[monitor://C:\Users\UserName\Desktop\splunk_monitor\testing.txt]
Verified using `splunk list monitor`. ( Please see attachment).
What could be going wrong here? The agent is sending regular event viewer data back to the indexer.. just not for the file modifications.
Please advise.
Thanks,
~ Abhi
[1]: /storage/temp/93172-splunk-list-monitor.jpg
↧