Splunk Search

wildcards and inputs.conf -- directory recursion

Steve_G_
Splunk Employee
Splunk Employee

Trying to understand exactly how directory recursion works in inputs.conf.

Specifically, how does /foo/.../.../.log resolve? Does it recurse through the same set of directories as /foo/.../.log ?

Also, can you use "*" in a directory segment to narrow things down a bit? For example: /foo/b*r/.log instead of /foo/.../.log ?

Tags (1)
1 Solution

bwooden
Splunk Employee
Splunk Employee

Yes, monitoring...

/foo/.../.../.log

would monitor .log as would the preferred

/foo/.../.log

Additionally, you can use an asterisk within a path as you reference in

/foo/b*r/.log

...to monitor either /foo/bar/.log or /foo/banbar/.log but neither /foo/bar/lorem/.log nor /foo/lorem/bar/.log

The reason is that 3 consecutive dots represent recursing through any number of directories while an asterisk is a wildcard.

View solution in original post

bwooden
Splunk Employee
Splunk Employee

Yes, monitoring...

/foo/.../.../.log

would monitor .log as would the preferred

/foo/.../.log

Additionally, you can use an asterisk within a path as you reference in

/foo/b*r/.log

...to monitor either /foo/bar/.log or /foo/banbar/.log but neither /foo/bar/lorem/.log nor /foo/lorem/bar/.log

The reason is that 3 consecutive dots represent recursing through any number of directories while an asterisk is a wildcard.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...