<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs not forwarding after Log Rotation in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529869#M4187</link>
    <description>&lt;P&gt;Hi our logs stop forwarding for a while after they have been archived, and this causes us to miss out on valuable data, how can I make splunk start monitoring that log after the old one has been renamed and archived ?&lt;/P&gt;</description>
    <pubDate>Wed, 18 Nov 2020 08:42:14 GMT</pubDate>
    <dc:creator>sphiwee</dc:creator>
    <dc:date>2020-11-18T08:42:14Z</dc:date>
    <item>
      <title>Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529869#M4187</link>
      <description>&lt;P&gt;Hi our logs stop forwarding for a while after they have been archived, and this causes us to miss out on valuable data, how can I make splunk start monitoring that log after the old one has been renamed and archived ?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 08:42:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529869#M4187</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-11-18T08:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529911#M4189</link>
      <description>&lt;P&gt;Please share the inputs.conf stanza for the files in question.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 13:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529911#M4189</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-18T13:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529955#M4192</link>
      <description>&lt;P&gt;where can I find that file?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 16:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529955#M4192</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-11-18T16:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529964#M4193</link>
      <description>&lt;P&gt;It's on the forwarder.&amp;nbsp; Or you can run btool on the forwarder.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list | grep -v "system\/default"&lt;/LI-CODE&gt;&lt;P&gt;Just copy and paste the stanza for the rotated files.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 16:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/529964#M4193</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-18T16:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530039#M4196</link>
      <description>&lt;P&gt;hi&lt;BR /&gt;&lt;BR /&gt;I don't want the rotated log because its being archived, I want the new log that's been generated.. because somehow after log rotation logs stop being forwarded.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 07:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530039#M4196</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-11-19T07:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530083#M4197</link>
      <description>&lt;P&gt;That is understood.&amp;nbsp; The solution is to correct your inputs.conf file, but we have to see the current setting to know what needs correcting.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 13:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530083#M4197</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-19T13:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530132#M4203</link>
      <description>&lt;P&gt;[default]&lt;BR /&gt;index = default&lt;BR /&gt;_rcvbuf = 1572864&lt;BR /&gt;host = $decideOnStartup&lt;/P&gt;&lt;P&gt;[blacklist:$SPLUNK_HOME/etc/auth]&lt;/P&gt;&lt;P&gt;[blacklist:$SPLUNK_HOME/etc/passwd]&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/splunk]&lt;BR /&gt;index = _internal&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/watchdog/watchdog.log*]&lt;BR /&gt;index = _internal&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/splunk/license_usage_summary.log]&lt;BR /&gt;index = _telemetry&lt;/P&gt;&lt;P&gt;[monitor://$SPLUNK_HOME/var/log/splunk/splunk_instrumentation_cloud.log*]&lt;BR /&gt;index = _telemetry&lt;BR /&gt;:&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 21:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530132#M4203</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-11-19T21:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530222#M4213</link>
      <description>&lt;P&gt;Which stanza is causing the problem?&amp;nbsp; IOW, what is the name of the rotated file?&lt;/P&gt;&lt;P&gt;I suspect the&amp;nbsp;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;[monitor://$SPLUNK_HOME/var/log/watchdog/watchdog.log*]&lt;/FONT&gt; or&amp;nbsp;&lt;FONT face="courier new,courier"&gt;[monitor://$SPLUNK_HOME/var/log/splunk/splunk_instrumentation_cloud.log*]&lt;/FONT&gt; stanza is the cause and the rotated files have an additional extension after ".log" (like ".log.gz", for instance).&amp;nbsp; If so, the solution is to add a blacklist attribute to the stanza(s) so files with the rotated extension are ignored.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 14:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530222#M4213</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-20T14:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530374#M4230</link>
      <description>&lt;P&gt;are you able to tell me what do these lines do&amp;nbsp;&lt;FONT face="courier new,courier"&gt;[monitor://$SPLUNK_HOME/var/log/watchdog/watchdog.log*]&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;or&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;[monitor://$SPLUNK_HOME/var/log/splunk/splunk_instrumentation_cloud.log*]&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;because watchdog.log and cloud.log are not the logs we are monitoring&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 06:33:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530374#M4230</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-11-23T06:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Logs not forwarding after Log Rotation</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530438#M4233</link>
      <description>&lt;P&gt;The first of those stanzas monitors files /opt/log/var/log/watchdog directory with names beginning with "watchdog.log".&amp;nbsp;&amp;nbsp;The second of the stanzas monitors files /opt/log/var/log/splunk directory with names beginning with "splunk_instrumentation_cloud.log".&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 14:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-not-forwarding-after-Log-Rotation/m-p/530438#M4233</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-23T14:34:27Z</dc:date>
    </item>
  </channel>
</rss>

