Getting Data In

Splunk forwarder on linux: parameter format error after adding monitor

thambisetty
SplunkTrust
SplunkTrust

Hi,
I have installed splunk forwarder on linux which is having symantec Brightmail Gateway.
and i tried to forward the data from that machine to splunk indexer that forwarder sending data only one file under the folder.
The path which i have given while adding the monitor:
'/var/log/mail/symantec/inbound'
under the inbound i want to read everything which has extension of type '.gz'
i am getting error that is "parameter should be in this format '-parameter value' "
while try to give the path like '/var/log/mail/symantec/inbound/*.gz'
can anyone tell me why its happening like that
please.......

————————————
If this helps, give a like below.
Tags (3)
0 Karma
1 Solution

Ayn
Legend

If you're adding things from the CLI, you need to make sure that your shell is not expanding wildcards for you. If you do

splunk add monitor /var/log/mail/symantec/inbound/*.gz

Your shell will expand this into all files that match that. In order to prevent that from happening you need to escape it, for instance by putting it in single quotes.

splunk add monitor '/var/log/mail/symantec/inbound/*.gz'

View solution in original post

Ayn
Legend

If you're adding things from the CLI, you need to make sure that your shell is not expanding wildcards for you. If you do

splunk add monitor /var/log/mail/symantec/inbound/*.gz

Your shell will expand this into all files that match that. In order to prevent that from happening you need to escape it, for instance by putting it in single quotes.

splunk add monitor '/var/log/mail/symantec/inbound/*.gz'

thambisetty
SplunkTrust
SplunkTrust

now i want to remove that which i added to monitor earlier.
May i konw how to do that.again i will add to monitor as u said

————————————
If this helps, give a like below.
0 Karma

MuS
SplunkTrust
SplunkTrust

Like the add command there is a remove command to remove monitor:

splunk remove monitor '/var/log/mail/symantec/inbound/*.gz'

cheers, MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...