Hi,
I'm trying to monitor 2 logs file format (.out & .err) from a same directory (/var/splunkdata).
I use the CLI command to execute the add monitor command :
sudo /opt/splunkforwarder/bin/splunk add monitor /var/splunkdata/*.out -index nbtktfed -sourcetype NBTKTFED.out
This command generate the following result :
Parameters must be in the form '-parameter value'
I don't know what i'm doing wrong.
Any idea ?
try:
./splunk add monitor -source "/var/splunkdata/*.out" -index nbtktfed -sourcetype "NBTKTFED.out"
try:
./splunk add monitor -source "/var/splunkdata/*.out" -index nbtktfed -sourcetype "NBTKTFED.out"
Thanks you !
You're welcome -source
is not mandatory but sometimes I have found it useful to specify it and "quote" the paths to make it clear to Splunk what you are trying to do.
Please upvote this answer to help others in the future!
All the best.