Monitoring Splunk

How to monitor dynamic log paths in splunk.

pbsuju
Explorer

I have log paths which varies always. How we can efficiently add a forwarder inputs ( inputs.conf)?.

/opt/selfHeal/modules/MW/MWPush/logs
/opt/selfHeal/modules/FW/autoUpdateBFBBot/logs
/opt/selfHeal/modules/AW/OSBot/logs
/opt/selfHeal/modules/ORA/ORABot/logs

I have added /opt/selfHeal/modules/.../logs in my forwarder inputs. But ii doesn't seems to be working.
I tried /opt/selfHeal/modules///logs.. that too doesn't work. Please advise..

Tags (1)
0 Karma

adonio
Ultra Champion

hello there,

please read here all the way through:
https://docs.splunk.com/Documentation/Splunk/7.1.0/Data/Specifyinputpathswithwildcards
try this:
[monitor:///opt/selfHeal/modules/.../.../logs]

hope it helps

0 Karma

pbsuju
Explorer

Tried with [monitor:///opt/selfHeal/modules/.../.../logs]. But it didn't work.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...