Splunk Search

how can i use a single character wildcard in inputs.conf?

Path Finder

I have a need to monitor files that look like this:

host one =


(yes the digits are there)... however if I monitor:

it's too greedy, I end up with the archive version (app rolls it's logs to:


I think this could work if there was a way to put a singler character wildcard, OR a regex - unfortunatly, since I need the * later sgement, I can't seem to get this to work in regex


Tags (3)


The path specified in monitor is not a regular expression. There is no single character wildcard. But you could do this

whitelist = /path/to/base/app/App\d{1}/App.*\.log

Because a whitelist (and the blacklist) are regular expressions.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!