<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex and wildcard  for inputs.conf file in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568770#M8607</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199978"&gt;@ashvinpandey&lt;/a&gt;&amp;nbsp; My monitoring stanzas are as below - still it does not work - in fact after adding monitoring stanza for access_log even catalina.out&amp;nbsp; has stopped getting monitored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when doing ./splunk list inputstatus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see below-&lt;/P&gt;&lt;P&gt;/hboprod/itdept/jira/domain/logs/access_log.2021-09-26&lt;BR /&gt;parent = //hboprod/itdept/jira/domain/logs/catalina.out&lt;BR /&gt;type = File did not match whitelist '^\/\/hboprod\/itdept\/jira\/domain\/logs/access_log[^/]*\.[^/]*$'.&lt;/P&gt;&lt;P&gt;/hboprod/itdept/jira/domain/logs/access_log.2021-09-27&lt;BR /&gt;parent = //hboprod/itdept/jira/domain/logs/catalina.out&lt;BR /&gt;type = File did not match whitelist '^\/\/hboprod\/itdept\/jira\/domain\/logs/access_log[^/]*\.[^/]*$'.&lt;/P&gt;&lt;P&gt;/hboprod/itdept/jira/domain/logs/access_log.2021-09-28&lt;BR /&gt;parent = //hboprod/itdept/jira/domain/logs/catalina.out&lt;BR /&gt;type = File did not match whitelist '^\/\/hboprod\/itdept\/jira\/domain\/logs/access_log[^/]*\.[^/]*$'.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 15:32:06 GMT</pubDate>
    <dc:creator>saad</dc:creator>
    <dc:date>2021-09-28T15:32:06Z</dc:date>
    <item>
      <title>Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568763#M8603</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I ahve below list of files in a directory and many more - below are few examples.....&lt;/P&gt;&lt;P&gt;210928105858:jira:HDL-APP004036:/hboprod/itdept/jira/domain/logs:$ ll&lt;BR /&gt;total 147936&lt;BR /&gt;-rw-r--r-- 1 jira jira 376923 Sep 26 23:59 access_log.2021-09-26&lt;BR /&gt;-rw-r--r-- 1 jira jira 1547320 Sep 28 00:00 access_log.2021-09-27&lt;BR /&gt;-rw-r--r-- 1 jira jira 891543 Sep 28 10:56 access_log.2021-09-28&lt;BR /&gt;-rw-r--r-- 1 jira jira 881194 Sep 28 10:02 atlassian-jira-gc-2021-09-20_11-52-13.log.0.current&lt;BR /&gt;-rw-r--r-- 1 jira jira 208279 Sep 28 10:49 atlassian-jira-gc-2021-09-28_10-04-10.log.0.current&lt;BR /&gt;-rw-r----- 1 jira jira 8964 Sep 20 11:52 catalina.2021-09-20.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 8965 Sep 28 10:04 catalina.2021-09-28.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 768821 Sep 28 10:12 catalina.out&lt;BR /&gt;-rw-r--r-- 1 jira jira 0 Sep 20 11:52 host-manager.2021-09-20.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 0 Sep 28 10:04 host-manager.2021-09-28.log&lt;BR /&gt;-rw-r----- 1 jira jira 0 Sep 17 00:14 localhost.2021-09-17.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 0 Sep 20 11:52 localhost.2021-09-20.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 0 Sep 28 10:04 localhost.2021-09-28.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 0 Sep 20 11:52 manager.2021-09-20.log&lt;BR /&gt;-rw-r--r-- 1 jira jira 0 Sep 28 10:04 manager.2021-09-28.log&lt;/P&gt;&lt;P&gt;I want to monitor catalina.out and access_log files only and not others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configure monitoring stanza for catalina.out and it is working as expected for me.&lt;/P&gt;&lt;P&gt;[monitor:////hboprod/itdept/jira/domain/logs/catalina.out]&lt;BR /&gt;sourcetype = log4j&lt;BR /&gt;ignoreOlderThan = 7d&lt;BR /&gt;crcSalt = &amp;lt;string&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need help for writing monitoring stanza for access_log as this files gets created daily with that days date in it name. How can i configure this files to be monitored?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568763#M8603</guid>
      <dc:creator>saad</dc:creator>
      <dc:date>2021-09-28T15:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568765#M8604</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238797"&gt;@saad&lt;/a&gt;&amp;nbsp;You can use the below stanza:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:////hboprod/itdept/jira/domain/logs/*.&amp;lt;file_extension&amp;gt;]&lt;/LI-CODE&gt;&lt;P&gt;You need to add the file extension and rest all remains the same.&lt;BR /&gt;Also, If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:16:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568765#M8604</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-28T15:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568766#M8605</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199978"&gt;@ashvinpandey&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have listed the file name in my orginal post, the file which i want to monitor is access_log and does not have any extension.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:18:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568766#M8605</guid>
      <dc:creator>saad</dc:creator>
      <dc:date>2021-09-28T15:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568768#M8606</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238797"&gt;@saad&lt;/a&gt;&amp;nbsp;Try using this:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:////hboprod/itdept/jira/domain/logs/access_log*.*]&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568768#M8606</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-28T15:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568770#M8607</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199978"&gt;@ashvinpandey&lt;/a&gt;&amp;nbsp; My monitoring stanzas are as below - still it does not work - in fact after adding monitoring stanza for access_log even catalina.out&amp;nbsp; has stopped getting monitored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when doing ./splunk list inputstatus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see below-&lt;/P&gt;&lt;P&gt;/hboprod/itdept/jira/domain/logs/access_log.2021-09-26&lt;BR /&gt;parent = //hboprod/itdept/jira/domain/logs/catalina.out&lt;BR /&gt;type = File did not match whitelist '^\/\/hboprod\/itdept\/jira\/domain\/logs/access_log[^/]*\.[^/]*$'.&lt;/P&gt;&lt;P&gt;/hboprod/itdept/jira/domain/logs/access_log.2021-09-27&lt;BR /&gt;parent = //hboprod/itdept/jira/domain/logs/catalina.out&lt;BR /&gt;type = File did not match whitelist '^\/\/hboprod\/itdept\/jira\/domain\/logs/access_log[^/]*\.[^/]*$'.&lt;/P&gt;&lt;P&gt;/hboprod/itdept/jira/domain/logs/access_log.2021-09-28&lt;BR /&gt;parent = //hboprod/itdept/jira/domain/logs/catalina.out&lt;BR /&gt;type = File did not match whitelist '^\/\/hboprod\/itdept\/jira\/domain\/logs/access_log[^/]*\.[^/]*$'.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568770#M8607</guid>
      <dc:creator>saad</dc:creator>
      <dc:date>2021-09-28T15:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568772#M8608</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199978"&gt;@ashvinpandey&lt;/a&gt;&amp;nbsp; My monitoring Stanza.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:////hboprod/itdept/jira/domain/logs/catalina.out]&lt;BR /&gt;sourcetype = log4j&lt;BR /&gt;ignoreOlderThan = 7d&lt;BR /&gt;crcSalt = &amp;lt;string&amp;gt;&lt;/P&gt;&lt;P&gt;[monitor:////hboprod/itdept/jira/domain/logs/access_log*.*]&lt;BR /&gt;sourcetype = log4j&lt;BR /&gt;ignoreOlderThan = 7d&lt;BR /&gt;crcSalt = &amp;lt;string&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568772#M8608</guid>
      <dc:creator>saad</dc:creator>
      <dc:date>2021-09-28T15:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568774#M8609</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238797"&gt;@saad&lt;/a&gt;&amp;nbsp;Check if this works ?&lt;BR /&gt;Also, If this reply helps you, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568774#M8609</guid>
      <dc:creator>ashvinpandey</dc:creator>
      <dc:date>2021-09-28T15:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568777#M8610</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199978"&gt;@ashvinpandey&lt;/a&gt;&amp;nbsp; what works? i think you missed something&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568777#M8610</guid>
      <dc:creator>saad</dc:creator>
      <dc:date>2021-09-28T15:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568781#M8611</link>
      <description>&lt;P&gt;Only the file extension is dynamic, so try something like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:////hboprod/itdept/jira/domain/logs/access_log.*]
sourcetype = YourSourcetypeHere
ignoreOlderThan = 7d
crcSalt = &amp;lt;string&amp;gt;&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568781#M8611</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-09-28T15:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Regex and wildcard  for inputs.conf file</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568785#M8612</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&amp;nbsp;Tried this as well - still the same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Regex-and-wildcard-for-inputs-conf-file/m-p/568785#M8612</guid>
      <dc:creator>saad</dc:creator>
      <dc:date>2021-09-28T15:53:41Z</dc:date>
    </item>
  </channel>
</rss>

