Hi Mayurrr98, thanks for you support on this but I am unable to monitor the "wtmpx|utmpx" file from the path /var/adm/ on the remote host. But we could monitor other files ".log|log$|message" are being ingested into splunk . Similarly for the second stanza also we are unable to monitor the "wtmp|btmp" files from the path /var/log/ on the remote host. But we could monitor other files ".log|log$|secure|message|auth|cron$|.out" are being ingested into splunk .
Since already we are able to get the other files "message|auth|cron" etc info in splunk, I did not change the regex, just added the new file name in the stanza along with other file name.
Kindly guide me how to fix this issue, we need to pull the wtmpx, utmpx, wtmp,btmp in splunk.
... View more