Maybe you can help me out with something. I have multiple files of the same type, error_log files, that are named different. An example would be /var/log/httpd/error_log, /var/log/httpd/error_log-1..etc.....the data input is set to be "/var/log/httpd/error_log*" what is the best way do this instead of having separate sources for these logs to have it under one source called access_log?
You can simply override the source setting either in the UI, while defining the new DataIput, or in the inputs.conf file, with something like:
[monitor:/var/log/httpd/error_log*]
disabled = false
followTail = 1
host = apache-1.splunk.com
sourcetype = access_combined
source = access_log
Hope that helps?
Cheers,
simuvid
You can simply override the source setting either in the UI, while defining the new DataIput, or in the inputs.conf file, with something like:
[monitor:/var/log/httpd/error_log*]
disabled = false
followTail = 1
host = apache-1.splunk.com
sourcetype = access_combined
source = access_log
Hope that helps?
Cheers,
simuvid
Awesome! works like a charm.. Thank you!