Getting Data In

Inputs.conf configuration to monitor 2 catalina log files in same directory with different formats and sourcetypes?

a212830
Champion

Hi,

I need to monitor two catalina logfiles that are in the same directory, but have different formats (and sourcetypes).

The naming convention is ../catalina.YYYY-MM-DD.log and catalina.out.YYYY-MM-DD.log

How would I setup inputs to handle this?

Tags (1)
1 Solution

somesoni2
Revered Legend

Try this in the inputs.conf

Updated

[monitor://your_directory/catalina.*.log] 
disabled = false 
followTail = 0 
sourcetype = your_sourcetype1
whitelist = catalina\.\d+-\d+-\d+\.log

[monitor://your_directory/catalina.out.*.log] 
disabled = false 
followTail = 0 
sourcetype = your_sourcetype2
whitelist = catalina\.out\.\d+-\d+-\d+\.log

View solution in original post

somesoni2
Revered Legend

Try this in the inputs.conf

Updated

[monitor://your_directory/catalina.*.log] 
disabled = false 
followTail = 0 
sourcetype = your_sourcetype1
whitelist = catalina\.\d+-\d+-\d+\.log

[monitor://your_directory/catalina.out.*.log] 
disabled = false 
followTail = 0 
sourcetype = your_sourcetype2
whitelist = catalina\.out\.\d+-\d+-\d+\.log

somesoni2
Revered Legend

My bad, I didn't read the question properly. Try the updated answer.

a212830
Champion

I have different sourcetypes that need to be mapped - the out goes to one sourcetype, the other to a different one. This doesn't appear to address that.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...