Getting Data In

I need help writing monitor stanza for a particular type of windows log files



I'm having issues getting some windows log files monitored properly.

The path is:

 D:\Program Files\Fidelity\Sametime 8.5.1 Gateway Health Check\STIM01WIN\logs\STGW51-STIM01WIN.log
 D:\Program Files\Fidelity\Sametime 8.5.1 Gateway Health Check\STIM02WIN\logs\STGW51-STIM02WIN.log

I need to monitor the logfile for each of these directories (there are many more, but they all follow the same naming convention).

I have the following, but it's not picking up the files.

[monitor://D:Program FilesFidelitySametime 8.5.1 Gateway Health CheckSTIM*logsST*-STI*.log]
index = euc_sametimedata
sourcetype = STGWHCLogs
followTail = 0

Any suggestions?

0 Karma


please don't use all caps in your postings. it makes it look like you're yelling. i have rewritten your title for you.

0 Karma


Try this...

[monitor://D:\Program Files\Fidelity\Sametime 8.5.1 Gateway Health Check\STIM*WIN\logs\STGW*-STIM*WIN.log]

Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...