Hello everyone,
I'm working to set up many Universal Forwarder to monitor a MFT logs.
MFT store all it's logs in the directory /data/mft/efs/logs/ .
In this directory, there are files and subdirectories that we do not want to monitor. The log files that we want to monitor are in subdirectories and these subdirectories rotate every day.
When MFT launches a flow for today, for exemple, it creates a sub-directory: /data/mft/efs/logs/2024-07-02/mft_flow.log
I created an inputs.conf file :
[default]
_meta=env::int-test
[monitor:///data/mft/efs/logs/*]
disabled=false
sourcetype=log4j
host=test-aws-lambda-splunk-code
followTail=0
whitelist=\d{4}-\d{2}-\d{2}\/.*\.log
index=test_filtre
 But I don’t get anything in my Splunk Enterprise.
Anyone can help me ? 
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi @michaelteck ,
did you tried:
[monitor:///data/mft/efs/logs/*/mft_flow.log]
disabled=false
sourcetype=log4j
host=test-aws-lambda-splunk-code
followTail=0
index=test_filtre?
Ciao.
Giuseppe
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi @michaelteck ,
did you tried:
[monitor:///data/mft/efs/logs/*/mft_flow.log]
disabled=false
sourcetype=log4j
host=test-aws-lambda-splunk-code
followTail=0
index=test_filtre?
Ciao.
Giuseppe
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi @michaelteck ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
