Getting Data In

I need help writing monitor stanza for a particular type of windows log files



I'm having issues getting some windows log files monitored properly.

The path is:

 D:\Program Files\Fidelity\Sametime 8.5.1 Gateway Health Check\STIM01WIN\logs\STGW51-STIM01WIN.log
 D:\Program Files\Fidelity\Sametime 8.5.1 Gateway Health Check\STIM02WIN\logs\STGW51-STIM02WIN.log

I need to monitor the logfile for each of these directories (there are many more, but they all follow the same naming convention).

I have the following, but it's not picking up the files.

[monitor://D:Program FilesFidelitySametime 8.5.1 Gateway Health CheckSTIM*logsST*-STI*.log]
index = euc_sametimedata
sourcetype = STGWHCLogs
followTail = 0

Any suggestions?

0 Karma

Splunk Employee
Splunk Employee

please don't use all caps in your postings. it makes it look like you're yelling. i have rewritten your title for you.

0 Karma


Try this...

[monitor://D:\Program Files\Fidelity\Sametime 8.5.1 Gateway Health Check\STIM*WIN\logs\STGW*-STIM*WIN.log]