Hi all, I've got the 4.1.5 Light Forwarder (64 bit) installed on a Windows 2008 (64 bit) server. I only have one directory structure and group of logs I'm trying to monitor with the following entry:
When I start up the forwarding software I do see the TCP connection between this server and my indexing system. But no data is being sent across. I've taken the log files from the above tree and placed them on C:\, adjusted my inputs.conf on the system and was able to read the data. Moving the test log file to a made up directory named C:\logs also worked. I copied the test log file to C:\Program Files and modified my inputs.conf and was able to read in the log file. But when I copied the test file to C:\Program Files (x86) and modified the inputs.conf accordingly I could not read the file.
Is there something with a special character like "(" or ")" that is confusing Splunk?
Probably the wildcards don't work. Try to configure it this way:
to monitor at upper directory level and include only files that match the whiltelist regular expression.
answered 25 Oct '10, 14:46
You probably need to escape the parentheses like so:
Also, be aware that you can use the
answered 25 Oct '10, 14:07