Splunk documentation is incorrect, as it states you should be able to do something like this :
[monitor:///ebs/*/var/log/access.log]
and it should pick up al these:
/ebs/why/var/log/access.log
/ebs/doesnt/var/log/access.log
/ebs/this/var/log/access.log
/ebs/work/var/log/access.log
so my question is, how do we do this?
 
					
				
		
Did you try explicitly setting recursive = true?
Reference: Inputs.conf
