<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Watch Multiple Log Files with Similar Names with Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577658#M102044</link>
    <description>&lt;P&gt;No data at all&lt;/P&gt;</description>
    <pubDate>Tue, 07 Dec 2021 15:56:11 GMT</pubDate>
    <dc:creator>yourknightmares</dc:creator>
    <dc:date>2021-12-07T15:56:11Z</dc:date>
    <item>
      <title>How to Watch Multiple Log Files with Similar Names with Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577547#M102020</link>
      <description>&lt;P&gt;Hi, I'm setting up Splunk Universal Forwarder to watch logs generated from an application I have in AWS Elastic Beanstalk. This is done by running shell script installing the Universal Forwarder and setting up monitors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simple enough. The problem is my application logs into a rolling file, meaning after a certain amount of data has been entered into the file (10MB in this example) it then creates a new file in the same location named "example 1.log" then "example 2.log", etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently I've tried using the below command to set up all the monitors with no success:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/opt/splunkforwarder/bin/splunk add monitor "/var/logs/example*"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I capture all the files it will create?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 06:03:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577547#M102020</guid>
      <dc:creator>yourknightmares</dc:creator>
      <dc:date>2021-12-07T06:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to Watch Multiple Log Files with Similar Names with Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577553#M102021</link>
      <description>&lt;P&gt;What is the issue? Are you getting duplicate data or no data at all?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 06:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577553#M102021</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-12-07T06:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to Watch Multiple Log Files with Similar Names with Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577658#M102044</link>
      <description>&lt;P&gt;No data at all&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 15:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Watch-Multiple-Log-Files-with-Similar-Names-with/m-p/577658#M102044</guid>
      <dc:creator>yourknightmares</dc:creator>
      <dc:date>2021-12-07T15:56:11Z</dc:date>
    </item>
  </channel>
</rss>

