Hi
I have log files on this path /opt/logs/*
add them to splunk and create index for this path, but when I search with source=“/opt/logs/*” no result return.
when i use index=“My-indexname” return result.
any idea?
Thanks,
Hi
just select verbose mode and look what Splunk said it’s source in left side. You could also click that field on left side and select “show field” (or something similar). Normally this field has shown automatically on event area.
r. Ismo