Monitoring Splunk

How do we read logs under the daily format directory?

thirulog
New Member

I have logs under the daily date format directory

How I ready the logs?

Directory : E:\Ora\DRM\daillyDate\log.txt

Tags (1)
0 Karma

woodcock
Esteemed Legend

Options are plenteous, there is also this:

[monitor://E:\Ora\DRM\...\log.txt]
0 Karma

lycollicott
Motivator

Monitor the directory E:\Ora\DRM and it will index everything below that.

(NOTE: You can use wildcards, but that doesn't mean you should use wildcards. )

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Wildcards are allowed in file paths. Try

[monitor://E:\Ora\DRM\*\log.txt]
---
If this reply helps you, Karma would be appreciated.
0 Karma

woodcock
Esteemed Legend

perhaps missing a path segment there?

0 Karma

thirulog
New Member

I have [monitor://E:\Ora\DRM**.txt] but did not work

Daily date directory created for every day and there are 20 logs under the date directory

0 Karma

woodcock
Esteemed Legend

I think that he meant this:

[monitor://E:\Ora\DRM\*\*\log.txt]
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...