Getting Data In

Attempting to index a apache logs directory

jslocomb
New Member

I am attempting to index a apache logs directory.

We use cronolog to split our apache log files We have a sub directory rotate_logs that have historical logs in GZ format.

I want to only index the error log files in /etc/httpd/logs and not the access logs or any time from subdirectories.

Tags (1)
0 Karma

southeringtonp
Motivator

Sounds like you want a blacklist on the filename. You can also turn off recursion if you don't want to descend into subdirectories.

For example:

[monitor:///etc/httpd/logs]
recursive = false
blacklist = \.gz$

Take a look at:
http://www.splunk.com/base/Documentation/4.1.5/admin/Inputsconf

and:
http://www.splunk.com/base/Documentation/4.1.5/admin/Whitelistorblacklistspecificincomingdata#Blackl...

Genti
Splunk Employee
Splunk Employee

directory structure and exact filenames desired would help too

0 Karma

Simeon
Splunk Employee
Splunk Employee

It would help to have your current settings and parameters used for this input.

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...