Getting Data In

Specifying a catch-all in inputs.conf?

mickeander
Loves-to-Learn

Hi,

 

If i have a directory structure like this:

/logs/server1

/logs/server2

/logs/server3

 

And i have set specific inputs.conf stanzas for server 1,2 and 3, but i also want to catch everything that ends up in /logs/, could i set the server1-3 stanzas and have a catch all stanza, or will that catch all stanza collect the logs from server 1-3 again?

 

 

 

 

[monitor:///logs/server1]
host_segment = 2
index = foo
sourcetype = aaa

[monitor:///logs/server3]
host_segment = 2
index = bar
sourcetype = bbb

[monitor:///logs/server3]
host_segment = 2
index = baz
sourcetype = ccc

[monitor:///logs]
index = unknown

 

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...