Getting Data In

how can I put a "+" in monitor:// path ?

ktn01
Path Finder

Hello,

I have the following stanza in input.conf

[monitor:///ccv/app/oracle/diag/asm/+asm/+ASM*/trace/alert_+ASM*.log]
index = cei_oracle
sourcetype = oracle:asm:log
_TCP_ROUTING = val_idx-group

and file /ccv/app/oracle/diag/asm/+asm/+ASM1/trace/alert_+ASM1.log would not been indexed.

I modifie de path replacing every "+" with a "" `[monitor:///ccv/app/oracle/diag/asm/*asm/*ASM/trace/alert_ASM.log]
` and then the file is indexed.

How can I put a "+" on my path definition?

Thanks

Christian

0 Karma

somesoni2
Revered Legend

Try escaping it using backward slash.

[monitor:///ccv/app/oracle/diag/asm/\+asm/\+ASM*/trace/alert_\+ASM*.log]
0 Karma

Anu
Path Finder

@somesoni2  still didn't work for me.. Do you have any workaround for getting asm alert log in to splunk??

0 Karma

ktn01
Path Finder

Thanks,

escaping with \ is working fine...

Christian

0 Karma

somesoni2
Revered Legend

Glad it worked for you. Please close the question by accepting the answer that worked.

0 Karma

alemarzu
Motivator

Hi there, try this out.

[monitor:///ccv/app/oracle/diag/asm/.../trace/alert_*ASM*.log]
0 Karma

ktn01
Path Finder

Thanks but /.../ is to generic in this case

Christian

0 Karma
Get Updates on the Splunk Community!

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...