Getting Data In

What is the proper use of (*) wildcard in a file monitor path?

Log_wrangler
Builder

So I am confused about how to write a wildcard path for the following.

I have a UF set up to monitor a file location.

For example [.. /opt/App1/App1-1234/logs ] contains some ( .log and .log.gz ) files I want to send to the indexers.

I tested with absolute path /opt/App1/App1-1234/App1-app.log and the logs rolled into Splunk just fine
Next I tried /opt/App1/App1*/logs < but that does not work.

What is the correct way to write this ? /opt/App1/App1*/logs/* ???

Please advise.

Thank you

Tags (2)
0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

It looks like you have an extra directory specified based on the original text.

/opt/App1/App1-1234/App1-app.log
/opt/App1/App1*/logs
/opt/App1/App1*/logs/*

This will work for files without the extra "logs" directory.

[monitor:///opt/App1/App1*/*]

But, if you need to recurse directories, you will have to use this:

[monitor:///opt/App1/.../logs/*]

Reference -> https://docs.splunk.com/Documentation/Splunk/latest/Data/Specifyinputpathswithwildcards

View solution in original post

0 Karma

jconger
Splunk Employee
Splunk Employee

It looks like you have an extra directory specified based on the original text.

/opt/App1/App1-1234/App1-app.log
/opt/App1/App1*/logs
/opt/App1/App1*/logs/*

This will work for files without the extra "logs" directory.

[monitor:///opt/App1/App1*/*]

But, if you need to recurse directories, you will have to use this:

[monitor:///opt/App1/.../logs/*]

Reference -> https://docs.splunk.com/Documentation/Splunk/latest/Data/Specifyinputpathswithwildcards

0 Karma

Log_wrangler
Builder

my bad, mistyped...

/opt/App1/App1-1234/logs/App1-app.log

thank you for confirming that /opt/App1/App1*/logs/* is a correct way to wildcard

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...