Getting Data In

How to configure inputs.conf to separate files monitored in a directory?

PPape
Contributor

Hey Guys,

I'm trying to index Data via File Monitor

[monitor://D:\CDR]
disabled = false
index = cdr
sourcetype = cdr

This works just fine, but now I want to separate the files in this Directory there are

cdr[generic Name]_[Date] 
and cmd[generic Name]_[Date]

so I tried

[monitor://D:\CDR]
disabled = false
index = cdr
sourcetype = cdr
whitelist = ^cdr

[monitor://D:\CDR]
disabled = false
index = cdr
sourcetype = cmr
whitelist = ^cmr

But this doesn't work.
EDIT: No Files are indexed when I use it like shown above

Is my RegEx wrong? What am I doing wrong?

Thanks for Helping!

Tags (2)
0 Karma
1 Solution

PPape
Contributor

The answer was:

 [monitor://D:\CDR\cdr*]
 disabled = false
 index = cdr
 sourcetype = cdr


 [monitor://D:\CDR\cmr*]
 disabled = false
 index = cdr
 sourcetype = cmr

Thanks to s72ucor in the #splunk Channel

View solution in original post

PPape
Contributor

The answer was:

 [monitor://D:\CDR\cdr*]
 disabled = false
 index = cdr
 sourcetype = cdr


 [monitor://D:\CDR\cmr*]
 disabled = false
 index = cdr
 sourcetype = cmr

Thanks to s72ucor in the #splunk Channel

Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...