Archive
Highlighted

inputs.conf is there a difference

Explorer

Hallo,

i only want to monitor files in the directory pkorb and not files in subdirectory pkorb/oldlogs
What is the right monitor ?

  1. [monitor:///var/log/pkorb]
  2. [monitor:///var/log/pkorb/]

or any other ?

Tags (1)
Highlighted

Re: inputs.conf is there a difference

SplunkTrust
SplunkTrust

I'd give this a shot:

[monitor:///var/log/pkorb]
recursive = false

Alternatively, this:

[monitor:///var/log/pkorb]
blacklist = oldlogs

The latter would recurse, but skip the oldlogs directory. See http://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/inputsconf for specs.

Highlighted

Re: inputs.conf is there a difference

SplunkTrust
SplunkTrust

[monitor:///var/log/pkorb/*] will forward any files sitting in the pkorb directory but will NOT forward files from sub-directories in that pkorb directory

If you wanted to ingest data from a subdirectory, it would look like

[monitor:///var/log/pkorb/.../*]

View solution in original post

Highlighted

Re: inputs.conf is there a difference

Explorer

thank you

0 Karma
Highlighted

Re: inputs.conf is there a difference

SplunkTrust
SplunkTrust

Did this answer your question? If so then please accept the answer

0 Karma
Highlighted

Re: inputs.conf is there a difference

Explorer

yes, this is what i am looking for.

0 Karma
Highlighted

Re: inputs.conf is there a difference

SplunkTrust
SplunkTrust

Can you please accept the answer and close it out?

0 Karma