Which of the following statements is true about data transformations using SEDCMD?
The ellipsis (...) in [monitor:///var/log/.../*.log] allows Splunk to monitor files ending in .log in all nested directories under /var/log/. [Reference: Splunk Docs on monitor stanza syntax]
Currently there are no comments in this discussion, be the first to comment!