Getting Data In

Wildcard to monitor in inputs.conf

SS1
Path Finder

Hi,

I have below log files under path /path/to/app/

usera-x.log

userb-x.log

userc-x.log

userd-y.log

usere-y.log

userf-z.log

userg-z.log

.

.

etc

To extract *-x.log i am using below inputs.conf, but the data isnt being indexed into splunk. Is there any issue with my inputs.conf

[monitor://E:\path\to\app\*-x.log]
disabled = 0
index = test
sourcetype = metric

0 Karma

Vardhan
Contributor

Hi,

Can you try with below syntax.

[monitor://E:\path\to\app\*x.log]
disabled = 0
index = test
sourcetype = metric

verify the path properly and check the internal logs are coming from the forwarder or not? And also is there any error in the splunkd.log ? 

0 Karma

SS1
Path Finder
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart the forwarder after modifying inputs.conf?

---
If this reply helps you, Karma would be appreciated.
0 Karma

SS1
Path Finder

Yes, I have restarted the forwarder but no luck. I am wondering if *- is causing any problems?

0 Karma

DaClyde
Contributor

The * shouldn't be a problem.  We use it extensively in our monitor stanzas, both as parts of filenames and as path segments.  Has your test index already been created?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...