<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ingest files with multiple dots in them in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-files-with-multiple-dots-in-them/m-p/540772#M90518</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/73614"&gt;@nls7010&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since monitor stanza supports regex you can try something below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///path/to/log/.*\-\d{8}\.\d+-\d+-\d+|.*\.\d\.log]&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 22 Feb 2021 06:55:00 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-02-22T06:55:00Z</dc:date>
    <item>
      <title>How to ingest files with multiple dots in them</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-files-with-multiple-dots-in-them/m-p/540530#M90501</link>
      <description>&lt;P&gt;I am trying to upload documents from a user who's log files has multiple dots in the naming convention:&lt;/P&gt;&lt;TABLE width="1259"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="499"&gt;&lt;P&gt;The logs have a *.0.1.log in its file extension, would it be possible to use *.*.*.log instead?&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="499"&gt;&lt;P&gt;The logs have a *-20210218.000023-5644-5716.0.log in its file extension, would it be possible to use *.*.*.*.log instead?&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="499"&gt;&lt;P&gt;The logs have a *-20201218.105324-11260-11240.0.log in its file extension, would it be possible to use *.*.*.log instead?&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="499"&gt;&lt;P&gt;The logs have a *-20210209.145105-16220-11864.0.log in its file extension, would it be possible to use *.*.*.log instead?&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="499"&gt;&lt;P&gt;The logs have a *-20201218.105324-25876-14744.0.log in its file extension, would it be possible to use *.*.*.log instead?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to get all of these from .log to .*.*.*.log into Splunk using one monitoring stanza?&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 19 Feb 2021 13:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-files-with-multiple-dots-in-them/m-p/540530#M90501</guid>
      <dc:creator>nls7010</dc:creator>
      <dc:date>2021-02-19T13:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest files with multiple dots in them</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-files-with-multiple-dots-in-them/m-p/540772#M90518</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/73614"&gt;@nls7010&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since monitor stanza supports regex you can try something below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///path/to/log/.*\-\d{8}\.\d+-\d+-\d+|.*\.\d\.log]&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 22 Feb 2021 06:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-files-with-multiple-dots-in-them/m-p/540772#M90518</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-22T06:55:00Z</dc:date>
    </item>
  </channel>
</rss>

