Splunk Enterprise

Use of wildcard in input.conf

jagdipSingh
New Member

Hi All,

I am using wildcard in inputs.conf since very long but recently when I am giving below path with wildcard splunk is not able to capture all the files:

[monitor://C:\logdir\*\*\Katre\log\*.log]

Around 178 files  should get selected with about monitor stanza but splunk forwarder is only send 20-30 files logs.  Am I hitting any limit or there is any limitation.

 

 

Labels (2)
0 Karma

vhharanpositka
Path Finder

Hi @jagdipSingh 

 

Please try this

[monitor://C:\logdir\*\*\Katre\log\*]

 

[monitor://C:\logdir\...\...\Katre\log\*]

 

Regards

0 Karma

jagdipSingh
New Member

@vhharanpositka  : is there any specific reason you told me to use [monitor://C:\logdir\*\*\Katre\log\*] rather than what I was using : [monitor://C:\logdir\*\*\Katre\log\*.log]

just asking to know what will it tune.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...