Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Unable to use regex to index logs

$
0
0
Hi, I wish to configure splunk forwarder to pick logs from a directory that match any of the below patterns. Essentially anything that matches the regex "/^(jacket.)?[^\.]*-[^\.]*(.jvm)?.log$/". I tried to make below changes to inputs.conf but it is not working as expected. Can someone help guide how to debug further ? - may start with “jacket.” - must have at least one hyphen - must end in “.log” or “.jvm.log” - must not have any other “.” characters #Inputs.conf [monitor:///base/apps/logs] disabled = false index = test sourcetype = _json whitelist = ^(jacket.)?[^\.]*-[^\.]*(.jvm)?.log$ blacklist = \.gz$

Viewing all articles
Browse latest Browse all 47296

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>