I'm watching a directory. Let's say it is /foo. The files are in subdirectories:
It doesn't appear Splunk is looking recursively to find those subdirectories. Do I need to add every individual month to Splunk? What are my options?
One thought is I could modify the archive script to put a copy of the file in the spool directory, but that means the index isn't "hard set" like it is on that monitored directory. What else? Perhaps I could have Splunk watch /foo/incoming, I'll copy it there and Splunk could read and delete it from that directory?
I think "..." is what I need for recursion. The inputs.conf doesn't make it clear- would the following monitor work: