Monitoring Splunk

How do we read logs under the daily format directory?

thirulog
New Member

I have logs under the daily date format directory

How I ready the logs?

Directory : E:\Ora\DRM\daillyDate\log.txt

Tags (1)
0 Karma

woodcock
Esteemed Legend

Options are plenteous, there is also this:

[monitor://E:\Ora\DRM\...\log.txt]
0 Karma

lycollicott
Motivator

Monitor the directory E:\Ora\DRM and it will index everything below that.

(NOTE: You can use wildcards, but that doesn't mean you should use wildcards. )

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Wildcards are allowed in file paths. Try

[monitor://E:\Ora\DRM\*\log.txt]
---
If this reply helps you, Karma would be appreciated.
0 Karma

woodcock
Esteemed Legend

perhaps missing a path segment there?

0 Karma

thirulog
New Member

I have [monitor://E:\Ora\DRM**.txt] but did not work

Daily date directory created for every day and there are 20 logs under the date directory

0 Karma

woodcock
Esteemed Legend

I think that he meant this:

[monitor://E:\Ora\DRM\*\*\log.txt]
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...