I have a custom application and the log gets created at 7:00 UTC every day. The log file will have timestamp in the filename. How do I configure the forwarder to send the file to Splunk indexer?
Example: /var/log/homerun-20200104.
In your inputs.conf monitor stanza you can use wildcards:
[monitor:///var/log/homerun-*]
index = foo
sourcetype = bar
etc.
In your inputs.conf monitor stanza you can use wildcards:
[monitor:///var/log/homerun-*]
index = foo
sourcetype = bar
etc.