<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitoring all auth.log file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76432#M15595</link>
    <description>&lt;P&gt;Hi there. i tried it but it only monitor auth.log and not the other auth.log file.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2013 01:26:11 GMT</pubDate>
    <dc:creator>darksky21</dc:creator>
    <dc:date>2013-09-30T01:26:11Z</dc:date>
    <item>
      <title>monitoring all auth.log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76430#M15593</link>
      <description>&lt;P&gt;Hi i would like to monitor all auth.log file in my ubuntu system but there are many auth.log file (e.g. auth.log, auth.log.1, auth.log.2.gz, auth.log.3.gz). How do i get splunk to monitor all of them? Currently am only able to monitor auth.log file only&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2013 15:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76430#M15593</guid>
      <dc:creator>darksky21</dc:creator>
      <dc:date>2013-09-29T15:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: monitoring all auth.log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76431#M15594</link>
      <description>&lt;P&gt;monitor the file and it's rotated versions.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[monitor:///var/log/auth.log*]&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2013 17:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76431#M15594</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-09-29T17:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: monitoring all auth.log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76432#M15595</link>
      <description>&lt;P&gt;Hi there. i tried it but it only monitor auth.log and not the other auth.log file.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 01:26:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76432#M15595</guid>
      <dc:creator>darksky21</dc:creator>
      <dc:date>2013-09-30T01:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: monitoring all auth.log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76433#M15596</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;Maybe it's a permissions issue or they all have the same header and Splunk, by defaults, think that already has indexed that file. You could try to add this to your inputs.conf file:&lt;/P&gt;

&lt;P&gt;crcSALT = &amp;lt; SOURCE &amp;gt;&lt;/P&gt;

&lt;P&gt;**Remove the blanks before and after SOURCE, and you dont need to put here your real source file, just the string SOURCE&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 09:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76433#M15596</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2013-09-30T09:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: monitoring all auth.log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76434#M15597</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I to have the same issue. we are monitoring the RSA key file from some host and we are getting logs from all the source excluding one source. the folder where auth.log file are fetched is present on that host  but splunk cant fetch the logs. the configuration of all the host are same and the permission to the auth.log dir is also same for all the servers. still not getting log.&lt;/P&gt;

&lt;P&gt;Please help here!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 08:23:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitoring-all-auth-log-file/m-p/76434#M15597</guid>
      <dc:creator>aktambe</dc:creator>
      <dc:date>2018-02-16T08:23:23Z</dc:date>
    </item>
  </channel>
</rss>

