Hello,
We would like to match all sources except the ones including /splunk/
in props.conf.
Example: No match for /opt/splunk/var/log/splunk/metrics.log
and /opt/splunk/var/log/splunk/splunkd.log
We tried several regex variations, but without luck...
Thanks,
Rainer
You should have the stanza match the source, not have a regex in the props.conf stanza. So the stanza should be something like [source::/opt/splunk/var/log/splunk/*]
If you want to see more examples have a look at your btool output - $SPLUNK_HOME/splunk cmd btool props list | grep 'source::'
See http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf and search the page for source:: for more details. If you're still having trouble post the relevant props and transforms stanzas here - you might have a different problem than the pattern matching
I suppose you could try this:
[source::(?!/opt/splunk/var/).../*]
Thanks! That did the trick...
What are you trying to achieve here? Are you trying to do a field extraction OR event filter OR something else?
we would like to implement index routing for all events but internal Splunk logs.