Getting Data In

Multiple Wildcards in inputs.conf

Path Finder


Can I use the following expression in my inputs.conf




Tags (1)

Splunk Employee
Splunk Employee

The simple wild cards for path are : * and ..., they are automatically replaced by regexes

It is not recommended to use regexes in the path (need to start to escape any special characters, by example file.txt has to be file\.txt ), instead you can use whitelist and blacklists that can contain regexes.

so with your case,
has to be something like

whitelist = .*MS?\.log\.gz

while the second should work because it uses only wildcards.


Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...