ok, my sources use syntax like \dir\dir\...\log so that it recursively finds all of my log files.
but now i see this in Splunk errors report (splunk v4.3.1 for linux)
03-19-2012 13:11:32.755 -0400 ERROR TailingProcessor - matching /logs/syslog/ironports/hostA/2012/03/ against ^/logs/syslog/ironports/.*/log$
The reason for the second one is that Splunk uses PCRE internally to implement the filters. The log message reflects the regex as used internally.