Getting Data In

use of wild card character in monitor path

spatil
Path Finder

Hi,

I have below log folders

C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\GN1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\FK1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\DK1\Performance\

I tried below monitor statments in inputs.conf

[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\...\Performance\]
[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\*\Performance\]

Using above statments no files are getting indexed , event count and index size is zero.

What should be the monitor path expected here .

Regards, S.

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi spatil

assuming you already checked this

http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards

  • does the user running splunk have read access to those directories?
  • maybe your path needs some quotes because of the space in it?

regards, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi spatil

assuming you already checked this

http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards

  • does the user running splunk have read access to those directories?
  • maybe your path needs some quotes because of the space in it?

regards, MuS

spatil
Path Finder

yes , already tried

0 Karma

MuS
SplunkTrust
SplunkTrust

have you tried [monitor://D:\logs...\Performance] ?

0 Karma

spatil
Path Finder

I moved my log files to other location say D:\logs and tried below monitor statments [monitor://D:\logs...\Performance] [monitor://D:\logs*\Performance]

0 Karma

MuS
SplunkTrust
SplunkTrust

how can the path be correct if you remove the spaces from the path? have you tried only with the // in the stanza?

0 Karma

spatil
Path Finder

added leading // in stanza, also removed space from monitor path, still index size is zero.
When I write whole path (removing wild cards) in monitor path , data is getting indexed. Want a solution for wild cards.

0 Karma

MuS
SplunkTrust
SplunkTrust

or you're just missing the leading // in your inputs.conf stanzas, like: [monitor://E:\foo*\log]

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...