Getting Data In

Need help for monitoring files

hrca33
Explorer

I am monitoring couple of files by specifying same source type.

Inputs.conf:-

[monitor://D:**\Installations*\Logs*\XYZ]
sourcetype = abc
index = ******
disabled = false
ignoreOlderThan = 2d

[monitor://D:**\Installations*\Logs*\fgh]
sourcetype = abc
index = ******
disabled = false
ignoreOlderThan = 2d

Now, I need to monitor the same path not individually mentioning the file names by using wildcards. Here I am using different source type.

[monitor://D:**\Installations*\Logs**.log]
sourcetype = xyz
index = ******
disabled = false
ignoreOlderThan = 2d

Is this works??

need help

Thanks

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi hrca33,
if your "XYZ" and "fhg" files have both ".log" extension, you could use
[monitor://D:\Installations\Logs**.log]

if they have different names and in the Log* directories there aren't other files with .log extension, you can use
[monitor://D:\Installations\Logs*]

if they have different names and in the directories there are other files easily identified (e.g.: .php), you can use
[monitor://D:
\Installations\Logs*]
blacklist = *.php

Bye.
Giuseppe

0 Karma

ddrillic
Ultra Champion

What about the index name? I see index = **. What's the intention?

0 Karma

hrca33
Explorer

Am using the same index.

0 Karma

ddrillic
Ultra Champion

Got it - does it work?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...