Getting Data In

use of wild card character in monitor path

spatil
Path Finder

Hi,

I have below log folders

C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\GN1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\FK1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\DK1\Performance\

I tried below monitor statments in inputs.conf

[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\...\Performance\]
[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\*\Performance\]

Using above statments no files are getting indexed , event count and index size is zero.

What should be the monitor path expected here .

Regards, S.

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi spatil

assuming you already checked this

http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards

  • does the user running splunk have read access to those directories?
  • maybe your path needs some quotes because of the space in it?

regards, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi spatil

assuming you already checked this

http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards

  • does the user running splunk have read access to those directories?
  • maybe your path needs some quotes because of the space in it?

regards, MuS

spatil
Path Finder

yes , already tried

0 Karma

MuS
SplunkTrust
SplunkTrust

have you tried [monitor://D:\logs...\Performance] ?

0 Karma

spatil
Path Finder

I moved my log files to other location say D:\logs and tried below monitor statments [monitor://D:\logs...\Performance] [monitor://D:\logs*\Performance]

0 Karma

MuS
SplunkTrust
SplunkTrust

how can the path be correct if you remove the spaces from the path? have you tried only with the // in the stanza?

0 Karma

spatil
Path Finder

added leading // in stanza, also removed space from monitor path, still index size is zero.
When I write whole path (removing wild cards) in monitor path , data is getting indexed. Want a solution for wild cards.

0 Karma

MuS
SplunkTrust
SplunkTrust

or you're just missing the leading // in your inputs.conf stanzas, like: [monitor://E:\foo*\log]

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>