Getting Data In

How to monitor a log file on UNIX where file name has date and PID which which are not static all the time.?

rohithmn3
New Member

Hi Team,

My file name looks like below:

SASMeta_MetadataServer_2017-04-21_auq4066l_9175164.log
<-----constant------->_<cur-date>_<host>_<PID>.log

How shall i monitor this file content, it's a rotating file and each day a new file gets created..!

inputs.conf

[monitor:///var/logs/system/local]
whitelist = 

What would be the whitelist for the above filename..!?
Please help here.

Regards,
Rohith

0 Karma
1 Solution

dineshraj9
Builder

You could configure the inputs this way -

[monitor:///var/logs/system/local/SASMeta_MetadataServer_*.log] 
index = index_name 
sourcetype = sourcetype_name
crcSalt=<SOURCE>

So any log file which starts with "SASMeta_MetadataServer_" will be read.

View solution in original post

0 Karma

dineshraj9
Builder

You could configure the inputs this way -

[monitor:///var/logs/system/local/SASMeta_MetadataServer_*.log] 
index = index_name 
sourcetype = sourcetype_name
crcSalt=<SOURCE>

So any log file which starts with "SASMeta_MetadataServer_" will be read.

0 Karma

rohithmn3
New Member

Hi Dinesh,

This monitor all files that starts with SASMeta_MetadataServer_*. In the above path there are multiple files and all starts with the same. So i don't want to monitor all. Is there a way i can only monitor the latest file..!?

0 Karma

dineshraj9
Builder

Hi Rohith,

You could add an ignoreOlderThan setting in inputs.conf.

http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Inputsconf

[monitor:///var/logs/system/local/SASMeta_MetadataServer_*.log] 
index = index_name 
sourcetype = sourcetype_name
crcSalt=<SOURCE>
ignoreOlderThan = 2d
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...