Hi,
I have log file with name of erlDirService_log.log and erlDirService_error.log.
I want to put this in blacklist in monitor stanza(inputs.conf).
So How should I do this ?
[monitor:///your/path]
blacklist = erlDirService_log\.log|erlDirService_error\.log
Yes and no - you can definitely do wildcarding, but it needs to be in regex syntax. Like erlDirService.*\.log
. But if you're doing this in a production environment and don't really know what you're doing, I would suggest you to read up on how this works.
Can we make this in single like (Just example, dont know in splunk)
blacklist = erlDirService*.log
I read the doc but its uncleared. I have to put this directly on production so i didnt try. I want to sure at first time.
What did you try that didn't work? What in the docs is unclear?