<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I ingest logs that have two dots in their name in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482734#M82704</link>
    <description>&lt;P&gt;look here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Specifyinputpathswithwildcards"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Specifyinputpathswithwildcards&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;*.*.log&lt;/CODE&gt; should work on your monitor stanza&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2020 13:33:59 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2020-04-24T13:33:59Z</dc:date>
    <item>
      <title>How do I ingest logs that have two dots in their name</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482733#M82703</link>
      <description>&lt;P&gt;I have a new client that has files named as follows:  xxxx.xxxx.log  Splunk is not ingesting them.  How can I ingest logs that have that type of naming convention.  I believe splunk is only looking at the xxx.xxx and can't match it to the /*.log stanza I have in the inputs.conf.  &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482733#M82703</guid>
      <dc:creator>nls7010</dc:creator>
      <dc:date>2020-04-24T13:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do I ingest logs that have two dots in their name</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482734#M82704</link>
      <description>&lt;P&gt;look here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Specifyinputpathswithwildcards"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Specifyinputpathswithwildcards&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;*.*.log&lt;/CODE&gt; should work on your monitor stanza&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:33:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482734#M82704</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2020-04-24T13:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do I ingest logs that have two dots in their name</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482735#M82705</link>
      <description>&lt;P&gt;I did put &lt;EM&gt;.&lt;/EM&gt;.log, but it still doesn't seem to be picking up the files.  &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-ingest-logs-that-have-two-dots-in-their-name/m-p/482735#M82705</guid>
      <dc:creator>nls7010</dc:creator>
      <dc:date>2020-04-24T13:37:24Z</dc:date>
    </item>
  </channel>
</rss>

