Getting Data In

Input stanza path is not absolute.

archspangler
Path Finder

How do I wildcard any windows drive letter in the inputs.conf stanza below?

inputs.conf

[monitor://[A-Z]:\Data\Disk1\*\MSSQL\Log\ERRORLOG*]
sourcetype = mssql:errorlog

Causes the below error...

07-16-2015 10:53:57.601 -0400 WARN  TailingProcessor - Input stanza path, '[A-Z]:\\Data\\Disk1\\*\\MSSQL\\Log\\ERRORLOG*' is not absolute.  This is a configuration error and may not work / break things.  Change this path to an absolute path.
Tags (2)
0 Karma

emiller42
Motivator

So this gets into how Splunk actually identifies what it needs to monitor. Take a more traditional monitor stanza like:

[monitor://C:\Data\Disk1\*\MSSQL\Log\ERRORLOG*]

When splunk sees the above, it goes to the deepest full path given C:\Data\Disk1\ and turns the rest of the stanza name into a regex-based whitelist which is checked against all children of the given path.

When your monitor stanza starts with a wildcard, it has no base path to enumerate in the first place. (Windows doesn't have an equivalent to /) Even if it did, this is a bad idea as Splunk will need to enumerate every single file on a system to see if it is a regex match of the desired path.

martin_mueller
SplunkTrust
SplunkTrust

To add an actual solution, just put up to 26 stanzas in your inputs.conf.

emiller42
Motivator

Yes, apologies I thought this was implied in my answer.

martin_mueller
SplunkTrust
SplunkTrust

It was, no worries.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...