<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Monitor Stazas in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320712#M59845</link>
    <description>&lt;P&gt;It worked. Thank you cusello:)&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2017 17:24:43 GMT</pubDate>
    <dc:creator>siva_cg</dc:creator>
    <dc:date>2017-07-20T17:24:43Z</dc:date>
    <item>
      <title>Splunk Monitor Stazas</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320709#M59842</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;We have a distributed environment with several forwarders managed by Deployment Server. Recently, I have configured few logs paths as below&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///appl_*/logs/wserv/]
whitelist = access_logs_wasLC*_PROD_\.\d{8}
blacklist = \.gz
recursive = true
index = was_logs
sourcetype = ibm:was:app

[monitor:///appl_*/logs/wserv/]
whitelist = access_logs_wasCC*_LUAT_\.\d{8}
blacklist = \.gz
recursive = true
index = luat_was_logs
sourcetype = ibm:was:app
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Both the Prod and LUAT environment servers are in the same server class. Now the issue is even the Prod logs are going to LUAT index. So could you please help me in resolving this issue? Is there any priority when the path is same?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 08:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320709#M59842</guid>
      <dc:creator>siva_cg</dc:creator>
      <dc:date>2017-07-20T08:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor Stazas</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320710#M59843</link>
      <description>&lt;P&gt;Hi siva_cg,&lt;BR /&gt;
try with this configuration:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///appl_/logs/wserv/access_logs_wasLCPROD.*]
blacklist = .gz
recursive = true
index = was_logs
sourcetype = ibm:was:app

[monitor:///appl_/logs/wserv/access_logs_wasCCLUAT.*]
blacklist = .gz
recursive = true
index = luat_was_logs
sourcetype = ibm:was:app
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 09:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320710#M59843</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-07-20T09:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor Stazas</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320711#M59844</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;We have regular expression in the whitelist. The exact whitelist value is as below:&lt;BR /&gt;
((access|error|access_ssl|error_ssl)&lt;EM&gt;log_was85CC[0-9]_A201_DigitalCA&lt;/EM&gt;(IBC|IBR|DQMU)&lt;EM&gt;LUAT*&lt;/EM&gt;[BW]1)?(|.\d{8}00)$&lt;/P&gt;

&lt;P&gt;So will this regular expression be included in the monitor path? I will use a wildcard before this regular expression but just want to know whether we can include regular expression in the monitor path?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:59:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320711#M59844</guid>
      <dc:creator>siva_cg</dc:creator>
      <dc:date>2020-09-29T14:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor Stazas</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320712#M59845</link>
      <description>&lt;P&gt;It worked. Thank you cusello:)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 17:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-Stazas/m-p/320712#M59845</guid>
      <dc:creator>siva_cg</dc:creator>
      <dc:date>2017-07-20T17:24:43Z</dc:date>
    </item>
  </channel>
</rss>

