Splunk Search

how can i use a single character wildcard in inputs.conf?

Path Finder

I have a need to monitor files that look like this:

host one =


(yes the digits are there)... however if I monitor:

it's too greedy, I end up with the archive version (app rolls it's logs to:


I think this could work if there was a way to put a singler character wildcard, OR a regex - unfortunatly, since I need the * later sgement, I can't seem to get this to work in regex


Tags (3)


The path specified in monitor is not a regular expression. There is no single character wildcard. But you could do this

whitelist = /path/to/base/app/App\d{1}/App.*\.log

Because a whitelist (and the blacklist) are regular expressions.