Hello,
I have the following stanza in input.conf
[monitor:///ccv/app/oracle/diag/asm/+asm/+ASM*/trace/alert_+ASM*.log]
index = cei_oracle
sourcetype = oracle:asm:log
_TCP_ROUTING = val_idx-group
and file /ccv/app/oracle/diag/asm/+asm/+ASM1/trace/alert_+ASM1.log
would not been indexed.
I modifie de path replacing every "+" with a "" `[monitor:///ccv/app/oracle/diag/asm/*asm/*ASM/trace/alert_ASM.log]
` and then the file is indexed.
How can I put a "+" on my path definition?
Thanks
Christian
Try escaping it using backward slash.
[monitor:///ccv/app/oracle/diag/asm/\+asm/\+ASM*/trace/alert_\+ASM*.log]
@somesoni2 still didn't work for me.. Do you have any workaround for getting asm alert log in to splunk??
Thanks,
escaping with \ is working fine...
Christian
Glad it worked for you. Please close the question by accepting the answer that worked.
Hi there, try this out.
[monitor:///ccv/app/oracle/diag/asm/.../trace/alert_*ASM*.log]
Thanks but /.../ is to generic in this case
Christian