Monitoring Splunk

Monitor directory containing Zip files

arunsundarm
Engager

I have enabled monitoring for zip files and there are two subfolders inside a zip file in that i have a text file LOG_ xxx which only iwant to monitor, I want to ignore the other files inside the zip file.

Also when i index splunk auto decompress the files and extracts as

file.zip:./folder1/folder2/Log_.txt
I only want the Log_
.txt

but splunk indexes all the files even if i give the source in the above format like: filename/.zip:./folder1/folder2/LOG_.txt

Need help

Tags (2)
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>