Getting Data In

Inputs.conf Not Picking Up What I expect

daniel333
Builder

I am trying to pull in a several log files that are always being updated from a folder on Windows. Here is my inputs.conf

[monitor://C:\Siebel\sba81\siebsrvr\BIN\*.log]
index=siebel
sourcetype=siebel_scg_logs

But the results in splunk only show one file ignoring all the other ones. Any idea why Splunk is not gathering the other log files in the directory? Did I miss something in the stanza I needed?

0 Karma

pradeepkumarg
Influencer

" * " doesn't work as expected in windows

This should work

[monitor://C:\Siebel\sba81\siebsrvr\BIN\]
index=siebel
sourcetype=siebel_scg_logs
whitelist=\.log$

lukejadamec
Super Champion

That is not exactly true, you just need to 'know' what to expect. If you want to get dizzy you can read the rules:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Specifyinputpathswithwildcards

My guess is that splunk is treating \* as regex not a * wildcard. Regardless, I believe the example in the doc says that \* does not work in Windows; you should expect it to fail.

0 Karma

Ayn
Legend

This script will help you in determining what status Splunk has for your monitor inputs: http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/

lukejadamec
Super Champion

You should post your monitor string as code (select the 101010 format option at the top).
Escape characters are important in a monitor string.

0 Karma

somesoni2
Revered Legend

Would it be possible for you to tell the filenames present in the folder?

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...