Splunk Search

Splunk forwarder log monitoring for unspecified stanzas

funlearning321
New Member

Hello,

can i please whether the splunk will monitor the logs which are not absolutely specified . For example , i have a log path as below:

/var/log/apache.log
/var/log/trans.log

which are specified as :

[monitor:///var/log/*.log]
disabled =false
followTail = 0
index =apache_application

sourcetype = web_logs

Will the /var/log/apache.log123423434.tmp also be monitored by the above monitoring stanza ?

Thanks

0 Karma

ddrillic
Ultra Champion

You can leave followTail = 0 out of the stanza ; -)

0 Karma

deepashri_123
Motivator

Hey@funlearning321,

The answer is no , that path won't be monitored.
Hope this helps!!

0 Karma

adonio
Ultra Champion

hello there,

please read this doc page in detail:
https://docs.splunk.com/Documentation/Splunk/7.1.0/Data/Specifyinputpathswithwildcards
also many answers here on this subject, here is an example:
https://answers.splunk.com/answers/7701/wildcards-with-inputs-conf.html

hope it helps

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...