Splunk Search
Highlighted

Regex in Whitelist, in inputs.conf regex help

Explorer

I'm trying to monitor log files within my application for the error & fatal logs, which can look like
web-error.log
web-error.log2018-02-01
web-error.log2018-02-02
web-error.log2018-02-02

There's other types of logs in the same directory that follows similar pattern such as web-info.log, web-debug.log, web-warn.log. For now, I'm having issues setting up monitoring just the web.log and all its archived logs.

My inputs.conf is setup with this:
[monitor:////wsbbat/web/dev/logs]
index=webdev
sourcetype = log4j
source = web
errors
whitelist = web-error.log*
crcSalt =

[monitor:////wsbbat/web/dev/logs]
index=webdev
sourcetype = log4j
source = web
fatal
whitelist = web-fatal.log*
crcSalt =

I've tried other whitelist pattern such as ones below but none of these patterns seems to work

whitelist = web-error.log$|web.log\d{4}-\d{2}-\d{2}
whitelist = web-error.log$|web.log\d{4}-\d{2}-\d{2}$
whitelist = web-error.log$|web.log[0-9-]+
whitelist = web-error.log$|web.log.*

0 Karma
Highlighted

Re: Regex in Whitelist, in inputs.conf regex help

SplunkTrust
SplunkTrust

Just use like this
Fixed typo

[monitor:////wsbbat/web/dev/logs/web-error.log*]
index=web_dev
sourcetype = log4j
source = web_errors

[monitor:////wsbbat/web/dev/logs/web-fatal.log*]
index=web_dev
sourcetype = log4j
source = web_fatal

View solution in original post

Highlighted

Re: Regex in Whitelist, in inputs.conf regex help

Explorer

BTW thanks. Trying it out now.

is the second one a typo
[monitor:////wsbbat/web/dev/logs/whitelist = web-fatal.log*]

did you mean
[monitor:////wsbbat/web/dev/logs/web-error.log*]
index=webdev
sourcetype = log4j
source = web
errors

[monitor:////wsbbat/web/dev/logs/web-fatal.log*]
index=webdev
sourcetype = log4j
source = web
fatal

0 Karma
Highlighted

Re: Regex in Whitelist, in inputs.conf regex help

Ultra Champion

Looks like it 🙂

0 Karma
Highlighted

Re: Regex in Whitelist, in inputs.conf regex help

Explorer

Thanks that worked for me.

0 Karma