Hello,
can i please whether the splunk will monitor the logs which are not absolutely specified . For example , i have a log path as below:
/var/log/apache.log
/var/log/trans.log
which are specified as :
[monitor:///var/log/*.log]
disabled =false
followTail = 0
index =apache_application
sourcetype = web_logs
Will the /var/log/apache.log123423434.tmp also be monitored by the above monitoring stanza ?
Thanks
You can leave followTail = 0
out of the stanza ; -)
Hey@funlearning321,
The answer is no , that path won't be monitored.
Hope this helps!!
hello there,
please read this doc page in detail:
https://docs.splunk.com/Documentation/Splunk/7.1.0/Data/Specifyinputpathswithwildcards
also many answers here on this subject, here is an example:
https://answers.splunk.com/answers/7701/wildcards-with-inputs-conf.html
hope it helps