Splunk Search

index files in same directory

stwong
Communicator

Hi all,

I'm a newbie to Splunk. I tried to index all apache log files in the same directory as a single source so that I can do searching of all files as a whole. However, each file becomes an independent source in the search page. Then I've to use multiple "source=" query to search records in different files.

Is it possible to make all files in the directory as a single source ?

Thanks a lot.
/ST Wong

Tags (2)
0 Karma
1 Solution

Ayn
Legend

There are ways to do this that require some messing around with on-the-fly transforming of the source value, but I wonder if you really need that? You can easily put a wildcard at the end when you search for the sources in the directory you're interested in, like so:

source="/the/directory/containing/apachelogs/*"

View solution in original post

Ayn
Legend

There are ways to do this that require some messing around with on-the-fly transforming of the source value, but I wonder if you really need that? You can easily put a wildcard at the end when you search for the sources in the directory you're interested in, like so:

source="/the/directory/containing/apachelogs/*"

Ayn
Legend

No problem. Could you please mark my answer as accepted? Thanks!

0 Karma

stwong
Communicator

thanks a lot.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...