Getting Data In

How to configure forwarder filename with timestamp

riyastk
Observer

I have a custom application and the log gets created at 7:00 UTC every day. The log file will have timestamp in the filename. How do I configure the forwarder to send the file to Splunk indexer?

Example: /var/log/homerun-20200104.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

In your inputs.conf monitor stanza you can use wildcards:

[monitor:///var/log/homerun-*]
index = foo
sourcetype = bar
etc.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

In your inputs.conf monitor stanza you can use wildcards:

[monitor:///var/log/homerun-*]
index = foo
sourcetype = bar
etc.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...