Splunk Search
Highlighted

Splunk forwarder log monitoring for unspecified stanzas

New Member

Hello,

can i please whether the splunk will monitor the logs which are not absolutely specified . For example , i have a log path as below:

/var/log/apache.log
/var/log/trans.log

which are specified as :

[monitor:///var/log/*.log]
disabled =false
followTail = 0
index =apacheapplication

sourcetype = web
logs

Will the /var/log/apache.log123423434.tmp also be monitored by the above monitoring stanza ?

Thanks

0 Karma
Highlighted

Re: Splunk forwarder log monitoring for unspecified stanzas

SplunkTrust
SplunkTrust

hello there,

please read this doc page in detail:
https://docs.splunk.com/Documentation/Splunk/7.1.0/Data/Specifyinputpathswithwildcards
also many answers here on this subject, here is an example:
https://answers.splunk.com/answers/7701/wildcards-with-inputs-conf.html

hope it helps

0 Karma
Highlighted

Re: Splunk forwarder log monitoring for unspecified stanzas

Motivator

Hey@funlearning321,

The answer is no , that path won't be monitored.
Hope this helps!!

0 Karma
Highlighted

Re: Splunk forwarder log monitoring for unspecified stanzas

Ultra Champion

You can leave followTail = 0 out of the stanza ; -)

0 Karma