Getting Data In

Recursive monitoring of directories "..." not working in Splunk 6.2

niklucky02
Explorer

I want to monitor /foo/log as well as /foo/bar/log and /foo/var/log. However, I am unable to using this our forwarder currently:

Inputs.conf:

[monitor:///foo/.../log]
0 Karma

woodcock
Esteemed Legend

The ... is any number of directories but what I think you need is * which is any single directory. In any case, either should work (but the former might lead to picking up unintended files/directories). Try the asterisk. Also, where did you place your inputs.conf file?

0 Karma

gcusello
Esteemed Legend

your command seems to be correct if the log filename to monitor is "log"!
I imagine that you already verified the connection between forwarder and indexer.
bye.
Giuseppe

0 Karma

niklucky02
Explorer

Yes, I have checked inputstatus/TailingProcessor:FileStatus for the forwarder and it says whitelist doesn't match

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...