Splunk Search

wildcard monitoring

a212830
Champion

Hi,

I'm doing some testing in my lab, and want to monitor all files in a directory that don't have .csv. I have the following in my inputs.conf

[monitor:///usr/local/nsmutils/export/current/]
index=perfstats
sourcetype=snmpinfo
followTail = 0
blacklist = .csv

However, nothing is getting indexed. Files are there and readable. I did a "oneshot" and the data looks good, but now I want to add it properly. Am I missing something? Somewhat related... I am also using this as an indexer. Do I need an outputs.conf in this situation, since the data is being indexed here? Could that be the problem?

Tags (1)
0 Karma

Dimitri_McKay
Splunk Employee
Splunk Employee

So you are looking at a folder and in it you have mixed software types. Is there a reason you aren't just naming out the types you have instead? Or are you just testing the blacklist functionality?

0 Karma

a212830
Champion

It's easier to do the blacklist - too many files to do a whitelist.

0 Karma
Get Updates on the Splunk Community!

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...