Getting Data In

How to configure inputs.conf to separate files monitored in a directory?

PPape
Contributor

Hey Guys,

I'm trying to index Data via File Monitor

[monitor://D:\CDR]
disabled = false
index = cdr
sourcetype = cdr

This works just fine, but now I want to separate the files in this Directory there are

cdr[generic Name]_[Date] 
and cmd[generic Name]_[Date]

so I tried

[monitor://D:\CDR]
disabled = false
index = cdr
sourcetype = cdr
whitelist = ^cdr

[monitor://D:\CDR]
disabled = false
index = cdr
sourcetype = cmr
whitelist = ^cmr

But this doesn't work.
EDIT: No Files are indexed when I use it like shown above

Is my RegEx wrong? What am I doing wrong?

Thanks for Helping!

Tags (2)
0 Karma
1 Solution

PPape
Contributor

The answer was:

 [monitor://D:\CDR\cdr*]
 disabled = false
 index = cdr
 sourcetype = cdr


 [monitor://D:\CDR\cmr*]
 disabled = false
 index = cdr
 sourcetype = cmr

Thanks to s72ucor in the #splunk Channel

View solution in original post

PPape
Contributor

The answer was:

 [monitor://D:\CDR\cdr*]
 disabled = false
 index = cdr
 sourcetype = cdr


 [monitor://D:\CDR\cmr*]
 disabled = false
 index = cdr
 sourcetype = cmr

Thanks to s72ucor in the #splunk Channel

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...