<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mulitiple Files in the same directory in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93988#M19559</link>
    <description>&lt;P&gt;Wow - a million files is definitely a performance problem. Are all the files "live" or are some of them stale? Check out some of the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; settngs - or better yet, move stale files to another directory after some appropriate time lapse (like a week).&lt;/P&gt;</description>
    <pubDate>Mon, 14 Oct 2013 08:51:21 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2013-10-14T08:51:21Z</dc:date>
    <item>
      <title>Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93981#M19552</link>
      <description>&lt;P&gt;I've seen the documentation and believe there is a way to dynamically do this with props.conf but I'm not understanding how to do it. I my case I'm working with 15 different source types with different file names, but at the same nested directory level.&lt;/P&gt;

&lt;P&gt;Only one works at a time, but if both are enabled, only the last one works. Both stanzas below are similar but one has disktool.txt and one has diskview.txt.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;inputs.conf
[monitor://\\host.share.comUploadDatasupportdata_Customers...*.disktool.txt] crcSalt = &amp;lt;source&amp;gt; index = eql_disktool sourcetype = disktool

[monitor://\\host.share.comUploadDatasupportdata_Customers...*.diskview.txt] crcSalt = &amp;lt;source&amp;gt; index = eql_diskview sourcetype = diskview
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2013 22:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93981#M19552</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2013-10-10T22:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93982#M19553</link>
      <description>&lt;P&gt;&lt;IMG src="http://jordan2000.com/misc/images/events.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Rule works as long as you only have one monitor stanza active otherwise it seems to conflict with others.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2013 23:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93982#M19553</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2013-10-10T23:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93983#M19554</link>
      <description>&lt;P&gt;There is definitely something wrong with shares.  I cannot get this to break on local drives.  I'll test it on shares tomorrow.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 00:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93983#M19554</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-11T00:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93984#M19555</link>
      <description>&lt;P&gt;For me, I get the same behavior on my local laptop with no share. Doesn't seem to like the combination of wilcard ... and a similar path. If I disable the last source, the next to last source starting indexing events &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 01:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93984#M19555</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2013-10-11T01:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93985#M19556</link>
      <description>&lt;P&gt;Try it without the crcsalt, and see if you get my results.  I have not used that yet, because it is bad juju.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 01:43:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93985#M19556</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-11T01:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93986#M19557</link>
      <description>&lt;P&gt;Thanks, will let you know&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 01:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93986#M19557</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2013-10-11T01:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93987#M19558</link>
      <description>&lt;P&gt;I'm now thinking this may be just a performance issue since a single indexer is trying to ingest more than a million files. It may be just working through one rule at a time. That would make sense why each rule works individually.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 21:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93987#M19558</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2013-10-11T21:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93988#M19559</link>
      <description>&lt;P&gt;Wow - a million files is definitely a performance problem. Are all the files "live" or are some of them stale? Check out some of the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; settngs - or better yet, move stale files to another directory after some appropriate time lapse (like a week).&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 08:51:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93988#M19559</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-10-14T08:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitiple Files in the same directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93989#M19560</link>
      <description>&lt;P&gt;I would recommend an approach similar to this:&lt;/P&gt;

&lt;P&gt;(inputs.conf on the forwarder)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://\\host.share.comUploadDatasupportdata_Customers]
whitelist = disk(view|tool)\.txt$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(props.conf on the forwarder &amp;amp; indexer)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::...diskview.txt]
sourcetype=diskview

[source:...disktool.txt]
sourcetype=disktool

[diskview]
TRANSFORMS-index = diskview-index

[disktool]
TRASNFORMS-index = disktool-index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(transforms.conf on the indexer)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[diskview-index]
DEST_KEY=_MetaData:Index
REGEX = .
FORMAT = diskview

[disktool-index]
DEST_KEY=_MetaData:Index
REGEX = .
FORMAT = disktool
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This avoids have overlapping (or nearly overlapping) monitor stanzas, and sets the sourcetype of each file by name.  Once the sourcetype is set, it uses index-time transforms to move the data into the correct indexes.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 13:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mulitiple-Files-in-the-same-directory/m-p/93989#M19560</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2013-10-14T13:31:27Z</dc:date>
    </item>
  </channel>
</rss>

