Hi,
How do I create a forwarder to get particular file from a directory, suppose want to index log file from 3 days only and in that directory files are older than a month how do I configure in Splunk forwarder.like
u_ex120201.log
u_ex120202.log
u_ex120203.log
u_ex120204.log
.
.
.
u_ex120312.log
u_ex120313.log
u_ex120314.log
Thanks.
I think these links will be useful for education purposes:
http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf
http://docs.splunk.com/Documentation/Splunk/latest/data/Specifyinputpathswithwildcards
A more direct answer is you might use something like this in your inputs.conf:
[monitor://path/to/file/u_ex*.log]
IgnoreOlderThan = 3d