Splunk Search

Problem with wildcard in inputs.conf?

SarahWKarvenz
Path Finder

I cannot seem to get my inputs.conf to accept the wildcard in the monitor string.
This is my inputs.conf file:

[default]
host = webLog

[monitor:///opt/log/www*]
index=web
host_segment=3

I get the following error in the splunkd.log:
ERROR TailingProcessor - matching /opt/log/www3/ against ^/opt/log/www[^/]*$

If I change my inputs to:
[monitor:///opt/log/www*]
index=web
host_segment=3

I get the following error in the splunkd.log:
ERROR TailingProcessor - matching /opt/log/www3/ against ^/opt/log/www[^/]*$

If I change it to:
[monitor:///opt/log/www1]
index=web
host_segment=3

It works and will grab all logs in the www1 folder.

Thanks!

Tags (1)

lguinn2
Legend

You need to use a different wild card for the directory name:

[monitor:///opt/log/www...]

Will work.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...