Hi,
I have below log folders
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\GN1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\FK1\Performance\
C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\DK1\Performance\
I tried below monitor statments in inputs.conf
[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\...\Performance\]
[monitor:C:\Program Files\Splunk\etc\apps\MyApp\Mylogs\*\Performance\]
Using above statments no files are getting indexed , event count and index size is zero.
What should be the monitor path expected here .
Regards, S.
Hi spatil
assuming you already checked this
http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards
regards, MuS
Hi spatil
assuming you already checked this
http://www.splunk.com/base/Documentation/latest/Data/Specifyinputpathswithwildcards
regards, MuS
yes , already tried
have you tried [monitor://D:\logs...\Performance] ?
I moved my log files to other location say D:\logs and tried below monitor statments [monitor://D:\logs...\Performance] [monitor://D:\logs*\Performance]
how can the path be correct if you remove the spaces from the path? have you tried only with the // in the stanza?
added leading // in stanza, also removed space from monitor path, still index size is zero.
When I write whole path (removing wild cards) in monitor path , data is getting indexed. Want a solution for wild cards.
or you're just missing the leading // in your inputs.conf stanzas, like: [monitor://E:\foo*\log]