It won't work with glob patterns. It can't. Remember - as I wrote before - if you have your events as an output of the search (and want to do some further analysis like | stat) splunk doesn't know anymore what were the criteria you were searching by. So my walkaround was not letting you match filenames from "the input". It was just predicting the output. You probably could do some magic to match with glob patterns or any other kind of match but that would involve either some kind of more complicated lookup matching or using some fancy evals.
... View more