Getting Data In

use of wild card character in monitor path

spatil
Path Finder

Hi,

I have below log folders

C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\GN1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\FK1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\DK1\Performance\

I tried below monitor statments in inputs.conf

[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\...\Performance\]
[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\*\Performance\]

Using above statments no files are getting indexed , event count and index size is zero.

What should be the monitor path expected here .

Regards, S.

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi spatil

assuming you already checked this

http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards

  • does the user running splunk have read access to those directories?
  • maybe your path needs some quotes because of the space in it?

regards, MuS

View solution in original post

MuS
Legend

Hi spatil

assuming you already checked this

http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards

  • does the user running splunk have read access to those directories?
  • maybe your path needs some quotes because of the space in it?

regards, MuS

spatil
Path Finder

yes , already tried

0 Karma

MuS
Legend

have you tried [monitor://D:\logs...\Performance] ?

0 Karma

spatil
Path Finder

I moved my log files to other location say D:\logs and tried below monitor statments [monitor://D:\logs...\Performance] [monitor://D:\logs*\Performance]

0 Karma

MuS
Legend

how can the path be correct if you remove the spaces from the path? have you tried only with the // in the stanza?

0 Karma

spatil
Path Finder

added leading // in stanza, also removed space from monitor path, still index size is zero.
When I write whole path (removing wild cards) in monitor path , data is getting indexed. Want a solution for wild cards.

0 Karma

MuS
Legend

or you're just missing the leading // in your inputs.conf stanzas, like: [monitor://E:\foo*\log]

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...