Installation

How would I initialize monitor command to pull the data/files from variable paths /locations?

SplunkDash
Motivator

Hello,

How would I initialize monitor command to pull the data/files from variable paths /locations? Some examples along with monitor command provided below:

Paths/Locations:

/RTAM/PROD_LOGS/PROD_DATA/2021-01-28_03-39-15/AUDITDATA/APPS/AUDITPROD.txt

/RTAM/PROD_LOGS/PROD_DATA/2021-01-29_09-12-12/AUDITDATA/APPS/AUDITPROD.txt

.........

..........

.........

/RTAM/PROD_LOGS/PROD_DATA/2021-02-02_06-19-10/AUDITDATA/APPS/AUDITPROD.txt

/RTAM/PROD_LOGS/PROD_DATA/2021-02-02_08-07-14/AUDITDATA/APPS/AUDITPROD.txt

Monitor Command I wrote:

[monitor://

/RTAM/PROD_LOGS/PROD_DATA/.../AUDITDATA/APPS/AUDITPROD.txt]

is this going to work to pull the data/files from all of the locations mentioned above? Any help/feedback will be highly appreciated. Thank you.

Labels (1)
0 Karma
1 Solution

SanjayReddy
SplunkTrust
SplunkTrust

Hi @SplunkDash 

instaed of ... (ellipsis wildcard) , please use(*)asterisk wildcard for moniting the path 

[monitor:///RTAM/PROD_LOGS/PROD_DATA/*/AUDITDATA/APPS/AUDITPROD.txt]

 

SanjayReddy_0-1646193106443.png

 

 

 

---
If this reply helps you, an upvote/Karma would be appreciated.

View solution in original post

SanjayReddy
SplunkTrust
SplunkTrust

Hi @SplunkDash 

instaed of ... (ellipsis wildcard) , please use(*)asterisk wildcard for moniting the path 

[monitor:///RTAM/PROD_LOGS/PROD_DATA/*/AUDITDATA/APPS/AUDITPROD.txt]

 

SanjayReddy_0-1646193106443.png

 

 

 

---
If this reply helps you, an upvote/Karma would be appreciated.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...