Hi
I have some log files with different name that copy into the Splunk server "/opt/splunk/logs" daily.
when I extract fields it just do this on specific file, while I need those field extract on every log on that path.
what is the solution here? I should define index for all logs and the extract field? is there any idea?
Thanks,
You can use this in props.conf:
[source:///Your/Partial/Path/Here/*]
Your Settings Here