I have a new client that has files named as follows: xxxx.xxxx.log Splunk is not ingesting them. How can I ingest logs that have that type of naming convention. I believe splunk is only looking at the xxx.xxx and can't match it to the /*.log stanza I have in the inputs.conf.
look here:
https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Specifyinputpathswithwildcards
*.*.log
should work on your monitor stanza
I did put ..log, but it still doesn't seem to be picking up the files.