Getting Data In

Recursive monitoring of directories "..." not working in Splunk 6.2

niklucky02
Explorer

I want to monitor /foo/log as well as /foo/bar/log and /foo/var/log. However, I am unable to using this our forwarder currently:

Inputs.conf:

[monitor:///foo/.../log]
0 Karma

woodcock
Esteemed Legend

The ... is any number of directories but what I think you need is * which is any single directory. In any case, either should work (but the former might lead to picking up unintended files/directories). Try the asterisk. Also, where did you place your inputs.conf file?

0 Karma

gcusello
SplunkTrust
SplunkTrust

your command seems to be correct if the log filename to monitor is "log"!
I imagine that you already verified the connection between forwarder and indexer.
bye.
Giuseppe

0 Karma

niklucky02
Explorer

Yes, I have checked inputstatus/TailingProcessor:FileStatus for the forwarder and it says whitelist doesn't match

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...