Getting Data In

Need help ingesting /var/log/mail.log.1

rene_splunk
Explorer

I have a number of log-rotated files for mail.log in the /var/log folder on a unix system. The /var/log/mail.log file gets ingested just fine, so I know permissions aren't an issue. However, I'd like to also ingest the older data that was log-rotated, but for the purpose of ingesting, those files were untarred again, so I have mail.log.1 to mail.log.4

I have tried numerous stanzas and regexes in the whitelist, but none lead to the older data getting ingested. 

The one I currently have in place is:


[monitor:///var/log/]
index = postfix
sourcetype = postfix_syslog
whitelist = (mail\.log$|mail\.log\.\d+)

Thanks for any suggestions in advance.

 

Labels (3)
0 Karma

rene_splunk
Explorer

Thanks Giuseppe,

I don't see any historical data in my index as yet, this is what's in the splunkd.log file

splunk_inputs.png

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rene_splunk,

please try this:

[monitor:///var/log/mail.log*]
index = postfix
sourcetype = postfix_syslog

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...