Hello,
I have a folder with several files on desktop. (xml) files have same names but different numbering for ex: File1, File2. File3
I also set up a sourcetype with event breaking that I tested and it is working (if I'm uploading a file having several events)
However when I set Monitor the folder c:\path\File* Choose a sourcetype that I have created, after reviewing I'm directed to search page where there is no single event (I think those files inside my folder are not indexed)
can anyone suggest what can be a reason?
A sample of the inputs.conf in a windows environment is below.
[monitor://C:\Program Files (x86)\Symantec\Symantec\data\dump\scm_admin.tmp]
sourcetype = symantec:ep:admin:file
index = symantec
disabled = false
make sure you are using the slashes correctly.
[monitor://C:\Users\Administrator\Desktop\Folder\BEX*]
This is my monitoring path.