I added this to my inputs.conf:
[monitor://C:\WINDOWS\system32\LogFiles\W3SVC*\]
disabled = false
followTail = 0
recursive = true
index=iis
ignoreOlderThan = 7d
When the deployment server gets the deployment app and reloads, the splunkd.log on the universal forwarder errors many times this error:
04-20-2012 10:14:14.368 -0700 ERROR TailingProcessor - matching C:\WINDOWS\system32\LogFiles\Cluster\ against ^C:\\WINDOWS\\system32\\LogFiles\\W3SVC[^\\]*\\$
04-20-2012 10:14:14.368 -0700 ERROR TailingProcessor - matching C:\WINDOWS\system32\LogFiles\HTTPERR\ against ^C:\\WINDOWS\\system32\\LogFiles\\W3SVC[^\\]*\\$
How do I get rid of this repeat error message?
I found this to work the best.
[monitor://C:\WINDOWS\system32\LogFiles\*\*.log]
disabled = false
followTail = 0
recursive = true
index=iis
ignoreOlderThan = 7d
sourcetype=MSWindows:2003:IIS
[monitor://C:\inetpub\logs\LogFiles\*\*.log]
disabled = false
followTail = 0
recursive = true
index=iis
ignoreOlderThan = 7d
sourcetype=MSWindows:2008R2:IIS
I found this to work the best.
[monitor://C:\WINDOWS\system32\LogFiles\*\*.log]
disabled = false
followTail = 0
recursive = true
index=iis
ignoreOlderThan = 7d
sourcetype=MSWindows:2003:IIS
[monitor://C:\inetpub\logs\LogFiles\*\*.log]
disabled = false
followTail = 0
recursive = true
index=iis
ignoreOlderThan = 7d
sourcetype=MSWindows:2008R2:IIS
I resolved it by removing the wildcard char. It must be a splunk forwarder error to repeat the error in the log.
ie
[monitor://C:WINDOWS\system32\LogFiles]
disabled = false
followTail = 0
recursive = true
index=iis
ignoreOlderThan = 7d