1:背景:
splunk 的forwarder server 上面有很多server 过来的文件,如下面:用户又想分类他们:
2: 方法:
[monitor:///abc/cohcv-500-*.log]
index = gopay_app_cohesity
disabled = false
ignoreOlderThan = 1d
followTail = 0
host = cohcv-500
sourcetype = cohcv-500
[monitor:///abc/cohcv-600-*.log]
index = gopay_app_cohesity
disabled = false
ignoreOlderThan = 1d
followTail = 0
host = cohcv-