I'm trying to monitor a catalina logs that look like this:
/home/loader/logs/catalina.2017-09-01.log
with this file monitor stanza:
[monitor:///home/loader/logs/catalina.*.log]
disabled = false
sourcetype = catalina
But I'm not seeing any data. Any reason why that wildcard would not match that file?
Thanks for the suggestions...turned out to be user error. 🙂 My wildcard DID match the file name.
You haven't told it what index to go to. Try this for a test:
[monitor:///home/loader/logs/catalina.*.log]
disabled = false
sourcetype = catalina
index = main
It should. For sanity check, I would put [monitor:///home/loader/logs/catalina.2017-09-01.log]
if you haven't done it yet... index=main?