- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello everyone,
I'm working to set up many Universal Forwarder to monitor a MFT logs.
MFT store all it's logs in the directory /data/mft/efs/logs/ .
In this directory, there are files and subdirectories that we do not want to monitor. The log files that we want to monitor are in subdirectories and these subdirectories rotate every day.
When MFT launches a flow for today, for exemple, it creates a sub-directory: /data/mft/efs/logs/2024-07-02/mft_flow.log
I created an inputs.conf file :
[default]
_meta=env::int-test
[monitor:///data/mft/efs/logs/*]
disabled=false
sourcetype=log4j
host=test-aws-lambda-splunk-code
followTail=0
whitelist=\d{4}-\d{2}-\d{2}\/.*\.log
index=test_filtre
But I don’t get anything in my Splunk Enterprise.
Anyone can help me ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @michaelteck ,
did you tried:
[monitor:///data/mft/efs/logs/*/mft_flow.log]
disabled=false
sourcetype=log4j
host=test-aws-lambda-splunk-code
followTail=0
index=test_filtre
?
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @michaelteck ,
did you tried:
[monitor:///data/mft/efs/logs/*/mft_flow.log]
disabled=false
sourcetype=log4j
host=test-aws-lambda-splunk-code
followTail=0
index=test_filtre
?
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @michaelteck ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
