Splunk Search

Problem with wildcard in inputs.conf?

SarahWKarvenz
Path Finder

I cannot seem to get my inputs.conf to accept the wildcard in the monitor string.
This is my inputs.conf file:

[default]
host = webLog

[monitor:///opt/log/www*]
index=web
host_segment=3

I get the following error in the splunkd.log:
ERROR TailingProcessor - matching /opt/log/www3/ against ^/opt/log/www[^/]*$

If I change my inputs to:
[monitor:///opt/log/www*]
index=web
host_segment=3

I get the following error in the splunkd.log:
ERROR TailingProcessor - matching /opt/log/www3/ against ^/opt/log/www[^/]*$

If I change it to:
[monitor:///opt/log/www1]
index=web
host_segment=3

It works and will grab all logs in the www1 folder.

Thanks!

Tags (1)

lguinn2
Legend

You need to use a different wild card for the directory name:

[monitor:///opt/log/www...]

Will work.

Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...