Getting Data In

How to configure stanzas in inputs.conf to monitor two paths with the same folder names, but are case sensitive?

rsathish47
Contributor

Hi All,

I need to configure inputs.conf for the folder path below. Can we do it in one stanza, or do we need create two different stanzas?
The difference between the two paths is the log folder name. In some servers, it is in lower case and in some servers it is in upper case.

Folder Path:

d:\Logs\TV_Engine.log
d:\logs\TV_Engine.log

Thanks
Sathish R

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

I think it is OS dependent, so since you are on Windows, you might only need one stanza.

I would use a single stanza, but I would do it like this:

[monitor://D:\*\TV_Engine.log]
sourcetype = tv_engine

This way doesn't matter what the folder is, as long as the file TV_Engine.log is 1 Folder down from D:\.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

I think it is OS dependent, so since you are on Windows, you might only need one stanza.

I would use a single stanza, but I would do it like this:

[monitor://D:\*\TV_Engine.log]
sourcetype = tv_engine

This way doesn't matter what the folder is, as long as the file TV_Engine.log is 1 Folder down from D:\.

rsathish47
Contributor

thank you @alacercogitatus
i thought the same.

i tried below but not worked

 [monitor://d:\(l|L)ogs\TV_Engine.log]
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Input stanzas cannot use Regex. * is a special character in this case.

0 Karma

rsathish47
Contributor

can we use like this
[monitor://d:\*ogs\TV_Engine.log]

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...