Getting Data In

Need help ingesting /var/log/mail.log.1

rene_splunk
Explorer

I have a number of log-rotated files for mail.log in the /var/log folder on a unix system. The /var/log/mail.log file gets ingested just fine, so I know permissions aren't an issue. However, I'd like to also ingest the older data that was log-rotated, but for the purpose of ingesting, those files were untarred again, so I have mail.log.1 to mail.log.4

I have tried numerous stanzas and regexes in the whitelist, but none lead to the older data getting ingested. 

The one I currently have in place is:


[monitor:///var/log/]
index = postfix
sourcetype = postfix_syslog
whitelist = (mail\.log$|mail\.log\.\d+)

Thanks for any suggestions in advance.

 

Labels (3)
0 Karma

rene_splunk
Explorer

Thanks Giuseppe,

I don't see any historical data in my index as yet, this is what's in the splunkd.log file

splunk_inputs.png

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rene_splunk,

please try this:

[monitor:///var/log/mail.log*]
index = postfix
sourcetype = postfix_syslog

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...