Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to edit my monitor stanza with wildcards to monitor a file with subfolders?

$
0
0
I need help with setting these wild cards, it seems like Splunk is not picking up the file in the sub folders. Logs are in: /opt/app/nv/vtest/test1/logs/mylLogs/file1/file2/testing/year/month/day/day/APP-blah-blah-bhal-LOG There is data in the sub folder in `/year/month/day/day`/, and then there are the file names that seem random, but start with APP and end with LOG. Below is what I have set up and no data is coming in. [monitor:///opt/app/nv/vtest/test1/logs/mylLogs/file1/file2/testing/.../.../.../.../APP*LOG] disabled = false recursive = false sourcetype = blah index = foofooblahhhhhh

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>