I am trying to use a Universal Forwarder to monitor some local files. I am editing the file $SPLUNK_HOME\etc\apps\Splunk_TA_windows\local\inputs.conf
, adding the following statement:
[monitor:///.../*.txt]
index = main
recursive = false
disabled = 0
It is my understanding that this will search the root directory and all sub-directories for any text files. Am I missing something? I haven't seen any new data appear on my Indexer.
That looks like a Unix file path, not Windows. Since I see this is within the Windows TA, shouldn't the path start with c:\ ?
There should be a backslash after the colon (website formatting nonsense)
I changed that now, so that it is
[monitor://c:...*.txt]
and still no luck.