[monitor://C:\*_IPCATMDetailLog.txt]
disable=0
index=test
sourcetype=IPCATMDetailLog
that is what I need to monitor. Because day by day the log will have date. For example: 20221219_IPCATMDetailLog.txt or 20221218_IPCATMDetailLog.txt etc.
I dont know why it just only can get log in 20221215 , before that I use default sourcetype by Splunk, I have use my sourcetype in afternoon 12/15/2022. The other days after that can not anymore.
I want to get all the log day by day following the sourcetype=IPCATMDetailLog.
Thanks for your help.