AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |
Back to Blog
Splunk inputs.conf crcsalt8/24/2023 Type "help " to get help with parameters for a specific command. splunk add monitor -source c:\windows\system32\LogFiles\W3SVC You can find the working version of nf below: monitor://C:\analysis\sysmon. splunk add monitor -source c:\Windows\windowsupdate.log -index newindex Hostsegmentnum number of segments in the file path to set as the host valueįollow-only only read from the end of the file (True|False, default=False) Hostregex regular expression of file path to set as the host value packedextensionslist: bz, bz2, tbz, tbz2, Z, gz, tgz, tar, zip. why to give blacklist of Specific extensions of compressed files to exclude, where splunk already ignores. Is there a way I can make crcSalt only apply to a certain subfolder or file type For example, here is my nf entry: monitor://c:varlogdata disabled fals. Hostname host name to set as the host value why do you have the crcSalt View solution in original post. My nf is configured to monitor a directory with may different subfolders, and each contains different types of log files. 353 nf about 346 attributes 346 blacklist, using 347 crcSalt. nf 0 Karma Reply 1 Solution Solution venkatasri SplunkTrust 06-08-2021 05:31 PM Hi balcv crcSalt
0 Comments
Read More
Leave a Reply. |