- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
I want to monitor files which keeps changing the filename according to the current date falling under respective month and year directory. Can anyone please help me out how can we monitor the same. I tried using wild card in the inputs.conf, but it seems to be not working.
Format:
D:\Logs\<dynamic-year>\<dynamic-month>\<dynamic-date>.txt
D:\Logs\2022\04\21042022.txt
I used the below config under inputs.conf
[monitor://D:\Logs\*\*\*.txt]
disabled = true
crcSalt = <SOURCE>
index = indexname
sourcetype = sourcetypename
Many Thanks in Advance!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"The asterisk wildcard matches anything in that specific folder path segment.
Unlike ..., * does not recurse through subfolders.".
You can read more about it in the docs: Specify input paths with wildcards - Splunk Documentation
I think your stanza should be working without that typo, but if it doesn't I would try (...).
I also noticed that you have disabled = true. If you want it active, it should be false.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I think your stanza should work with a small change - removing the double backslash
[monitor://D:\Logs\*\*\*.txt]
I personally would use ... like this:
[monitor://D:\Logs\...\*.txt]
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @smurf
Thanks for your response!
Apologies.. double slash was a typo, you mean just period (...) instead of wildcard and backslash (*\*)?
[monitor://D:\Logs\...\*.txt]
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"The asterisk wildcard matches anything in that specific folder path segment.
Unlike ..., * does not recurse through subfolders.".
You can read more about it in the docs: Specify input paths with wildcards - Splunk Documentation
I think your stanza should be working without that typo, but if it doesn't I would try (...).
I also noticed that you have disabled = true. If you want it active, it should be false.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many thanks @smurf this worked!! 🙂
data:image/s3,"s3://crabby-images/1a552/1a552ff33d37f94e7c5bc13132edaa973c529815" alt=""