<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the regex in inputs.conf not working for monitoring my log files? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314327#M94074</link>
    <description>&lt;P&gt;Hi, Thanks, but these files could be multiple levels down from the main directory&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2017 16:52:48 GMT</pubDate>
    <dc:creator>robertlynch2020</dc:creator>
    <dc:date>2017-04-06T16:52:48Z</dc:date>
    <item>
      <title>Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314323#M94070</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;I have the following file in multiple sub directories. I am trying to pick them up but the below is not working and i can't crack it.&lt;BR /&gt;
The regex is good, but it just won't take them it... any help would be super... I am thinking something very small is wrong here.&lt;/P&gt;

&lt;P&gt;-rw-rw-r--   1 autoengine murex       4772 Apr  6 17:24 mxtiming_730010_dell427srv_121.log&lt;BR /&gt;
-rw-rw-r--   1 autoengine murex       4772 Apr  6 17:26 mxtiming_730018_dell427srv_504.log&lt;BR /&gt;
-rw-rw-r--   1 autoengine murex       4772 Apr  6 17:27 mxtiming_730022_dell427srv_531.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///net/dell427srv//data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/.../*.log]
disabled = false
host = RSAT_Campaign
index = mlc_live
whitelist = mxtiming_\d+_\w+_\d+.*\.log$
sourcetype = MX_TIMING
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314323#M94070</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2020-09-29T13:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314324#M94071</link>
      <description>&lt;P&gt;Try this change:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [monitor:///net/dell427srv//data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/*/]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This assumes only a single directory layer between &lt;CODE&gt;QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART&lt;/CODE&gt; and your files.  Leave everything else the same.  Restart your forwarder's splunk instance.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 16:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314324#M94071</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-06T16:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314325#M94072</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
Can you share sn example of not wanted files?&lt;BR /&gt;
At a first sight you could insert part of filename in monitor&lt;BR /&gt;
[monitor://net/dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/.../mxtiming_*.log]&lt;BR /&gt;
Beware that there is a double slash in tour path.&lt;BR /&gt;
Every way you could change your regex in this way&lt;BR /&gt;
mxtiming_[^&lt;EM&gt;]+&lt;/EM&gt;[^&lt;EM&gt;]+&lt;/EM&gt;[^.]+.log&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:34:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314325#M94072</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T13:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314326#M94073</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have files like below that i don't want to take in.&lt;BR /&gt;
mxtiming_adaptposnbstoredpltables_20170306-093752167_44364646_6902.log&lt;BR /&gt;
mxtiming_removecommodityfuturesindexplinstruments_20170306-093752167_222279393_6902.log&lt;/P&gt;

&lt;P&gt;Cheers for you help&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314326#M94073</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2020-09-29T13:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314327#M94074</link>
      <description>&lt;P&gt;Hi, Thanks, but these files could be multiple levels down from the main directory&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 16:52:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314327#M94074</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2017-04-06T16:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314328#M94075</link>
      <description>&lt;P&gt;Hi No Luck, i tried this but nothing come out&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://net/dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/.../*.log]
disabled = false
host = RSAT_Campaign
index = mlc_live
whitelist = mxtiming_[^]+[^]+[^.]+.log$  
sourcetype = MX_TIMING
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Apr 2017 17:18:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314328#M94075</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2017-04-06T17:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314329#M94076</link>
      <description>&lt;P&gt;Can you please give the full path to a few of these?  Feel free to alter directory names as needed for confidentiality, but we need to see the way the full path looks in order to check some things.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314329#M94076</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-04-06T19:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314330#M94077</link>
      <description>&lt;P&gt;Hi robertlynch2020,&lt;BR /&gt;
sorry but I answered using my smartphone that has limited function keyboards!&lt;BR /&gt;
regex isn't correct, try:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;mxtiming_[^_]+_[^_]+_[^\.]+\.log$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 07:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314330#M94077</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-04-07T07:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314331#M94078</link>
      <description>&lt;P&gt;Thanks for your help on this , I think we are close.&lt;BR /&gt;
To explain the issues more.&lt;/P&gt;

&lt;P&gt;Wanted Files&lt;BR /&gt;
Any sub directory of the main &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART]

dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/X/Y/A/mxtiming_730010_dell427srv_121.log

Or 
dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/A/X/mxtiming_730018_dell427srv_504.log  
Or.
Etc..

mxtiming_730010_dell427srv_121.log
mxtiming_730018_dell427srv_504.log
mxtiming_730022_dell427srv_531.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Unwanted Files&lt;BR /&gt;
The files I don’t want are below and again they can also come into any subdirectory&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;mxtiming_commoditynearbyonindexhistoricaldata_20170306-093752167_1294331273_6902.log
mxtiming_commoditynearbyonindextofutures_20170306-093752167_1718781102_6902.log
mxtiming_datamartdatasetlabelstransfer_20170306-093752167_1714912538_6902.log
mxtiming_fillcommoditytimeunits_20170306-093752167_1066971732_6902.log
mxtiming_obsolete_typology_cleanup_in_stp_rights_20170306-093752167_1206801397_6902.log
mxtiming_new_stp_rights_migration_20170306-093752167_252516786_6902.log
mxtiming_adapt_warehouse_rebuild_20170306-093752167_1385637444_6902.log
mxtiming_updatepricingbookingpretraderouters_20170306-093752167_904493553_6902.log
mxtiming_collateralinterestopsobjectupgrade_20170306-093752167_1527129704_6902.log
mxtiming_refreshaccountssidata_20170306-093752167_421251909_6902.log

dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/X/Y/A/mxtiming_adaptposnbstoredpltables_20170306-093752167_44364646_6902.log
Or 
dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/A/Z/A/mxtiming_removecommodityfuturesindexplinstruments_20170306-093752167_222279393_6902.log
OR .
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;…etc..&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 09:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314331#M94078</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2017-04-07T09:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314332#M94079</link>
      <description>&lt;P&gt;Hi robertlynch2020,,&lt;BR /&gt;
try this one, it should be correct (see &lt;A href="https://regex101.com/r/8Mzm3g/1"&gt;https://regex101.com/r/8Mzm3g/1&lt;/A&gt;)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;mxtiming_(?&amp;lt;ppp&amp;gt;\d*_[^_]*_\d*)\.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 09:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314332#M94079</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-04-07T09:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314333#M94080</link>
      <description>&lt;P&gt;Thanks for your help on this , I think we are close.&lt;BR /&gt;
To explain the issues more.&lt;/P&gt;

&lt;P&gt;Wanted Files&lt;BR /&gt;
Any sub directory of the main&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART]

 dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/X/Y/A/mxtiming_730010_dell427srv_121.log

 Or 
 dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/A/X/mxtiming_730018_dell427srv_504.log    
 Or.
 Etc..

 mxtiming_730010_dell427srv_121.log
 mxtiming_730018_dell427srv_504.log
 mxtiming_730022_dell427srv_531.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Unwanted Files&lt;BR /&gt;
The files I don’t want are below and again they can also come into any subdirectory&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; mxtiming_commoditynearbyonindexhistoricaldata_20170306-093752167_1294331273_6902.log
 mxtiming_commoditynearbyonindextofutures_20170306-093752167_1718781102_6902.log
 mxtiming_datamartdatasetlabelstransfer_20170306-093752167_1714912538_6902.log
 mxtiming_fillcommoditytimeunits_20170306-093752167_1066971732_6902.log
 mxtiming_obsolete_typology_cleanup_in_stp_rights_20170306-093752167_1206801397_6902.log
 mxtiming_new_stp_rights_migration_20170306-093752167_252516786_6902.log
 mxtiming_adapt_warehouse_rebuild_20170306-093752167_1385637444_6902.log
 mxtiming_updatepricingbookingpretraderouters_20170306-093752167_904493553_6902.log
 mxtiming_collateralinterestopsobjectupgrade_20170306-093752167_1527129704_6902.log
 mxtiming_refreshaccountssidata_20170306-093752167_421251909_6902.log

 dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/X/Y/A/mxtiming_adaptposnbstoredpltables_20170306-093752167_44364646_6902.log
 Or 
 dell427srv/data1/apps/QCST_DBS_RSAT_v3.1.38_MASTER_DONOTRESTART/A/Z/A/mxtiming_removecommodityfuturesindexplinstruments_20170306-093752167_222279393_6902.log
 OR .
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 07 Apr 2017 09:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314333#M94080</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2017-04-07T09:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314334#M94081</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;So it looks like i get this to work, with the regex - thanks.&lt;BR /&gt;
whitelist = mxtiming_(?\d*&lt;EM&gt;[^&lt;/EM&gt;]&lt;EM&gt;_\d&lt;/EM&gt;).log&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:34:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314334#M94081</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2020-09-29T13:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314335#M94082</link>
      <description>&lt;P&gt;Hi - This worked thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 11:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314335#M94082</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2017-04-07T11:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the regex in inputs.conf not working for monitoring my log files?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314336#M94083</link>
      <description>&lt;P&gt;Hi - I tried this, but it only give me the subdirectories and not the main directory.&lt;/P&gt;

&lt;P&gt;So it looks like i need to lines in my inputs.conf to get the main directory and all its subdirectories&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///net/dell425srv/dell425srv/apps/SPLUNK_BACK_UP_LIVE/MXTIMING_MEDIUM5/*.log]
disabled = false
recursive = true
host = MXTIMING_LIVE_TEST5
index = mlc_live
whitelist = mxtiming_(?&amp;lt;ppp&amp;gt;\d*_[^_]*_\d*)\.log
crcSalt = &amp;lt;SOURCE&amp;gt;
sourcetype = MX_TIMING

[monitor:///net/dell425srv/dell425srv/apps/SPLUNK_BACK_UP_LIVE/MXTIMING_MEDIUM5/.../*.log]
disabled = false
recursive = true
host = MXTIMING_LIVE_TEST5
index = mlc_live
whitelist = mxtiming_(?&amp;lt;ppp&amp;gt;\d*_[^_]*_\d*)\.log
crcSalt = &amp;lt;SOURCE&amp;gt;
sourcetype = MX_TIMING
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 07 Apr 2017 11:27:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-regex-in-inputs-conf-not-working-for-monitoring-my/m-p/314336#M94083</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2017-04-07T11:27:12Z</dc:date>
    </item>
  </channel>
</rss>

