Getting Data In

Recursive monitoring of directories "..." not working in Splunk 6.2

niklucky02
Explorer

I want to monitor /foo/log as well as /foo/bar/log and /foo/var/log. However, I am unable to using this our forwarder currently:

Inputs.conf:

[monitor:///foo/.../log]
0 Karma

woodcock
Esteemed Legend

The ... is any number of directories but what I think you need is * which is any single directory. In any case, either should work (but the former might lead to picking up unintended files/directories). Try the asterisk. Also, where did you place your inputs.conf file?

0 Karma

gcusello
SplunkTrust
SplunkTrust

your command seems to be correct if the log filename to monitor is "log"!
I imagine that you already verified the connection between forwarder and indexer.
bye.
Giuseppe

0 Karma

niklucky02
Explorer

Yes, I have checked inputstatus/TailingProcessor:FileStatus for the forwarder and it says whitelist doesn't match

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...