<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Minimizing logging on Splunk Light Forwarder... in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13050#M205</link>
    <description>&lt;P&gt;You can tune the log levels and sizes in $SPLUNK_HOME/etc/log.cfg.  After editing this file, you will need to restart Splunk.&lt;/P&gt;

&lt;P&gt;The specific parameters you will want to edit are the maxFileSize and maxBackupIndex under each file type.&lt;/P&gt;

&lt;P&gt;I recommend you retain as much data as you can since this data is very useful for troubleshooting problems.   &lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2010 00:55:56 GMT</pubDate>
    <dc:creator>Simeon</dc:creator>
    <dc:date>2010-05-07T00:55:56Z</dc:date>
    <item>
      <title>Minimizing logging on Splunk Light Forwarder...</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13049#M204</link>
      <description>&lt;P&gt;Hey Guys, &lt;/P&gt;

&lt;P&gt;Just noticed that logging on one of my light forwarders is taking up a lot of space:&lt;/P&gt;

&lt;P&gt;myhost[05:15 PM]root:/opt/splunk/var/log/splunk# ls -lh&lt;/P&gt;

&lt;P&gt;total 113M  &lt;/P&gt;

&lt;P&gt;116K -rw-------  1 root root 111K May  6 17:10 audit.log&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:13 btool.log&lt;BR /&gt;
4.0K -rw-------  1 root root   61 Apr 26 15:13 first_install.log&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:31 intentions.log&lt;BR /&gt;
 12K -rw-------  1 root root 9.5K May  6 17:10 license_audit.log&lt;BR /&gt;
 15M -rw-------  1 root root  15M May  6 17:15 metrics.log&lt;BR /&gt;
 24M -rw-------  1 root root  24M May  5 10:12 metrics.log.1&lt;BR /&gt;
 24M -rw-------  1 root root  24M May  3 05:22 metrics.log.2&lt;BR /&gt;
 24M -rw-------  1 root root  24M May  1 00:30 metrics.log.3&lt;BR /&gt;
 24M -rw-------  1 root root  24M Apr 28 19:48 metrics.log.4&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:31 scheduler.log&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:31 searches.log&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:31 searchhistory.log&lt;BR /&gt;
2.0M -rw-------  1 root root 2.0M May  6 17:10 splunkd.log&lt;BR /&gt;
556K -rw-------  1 root root 551K May  6 17:10 splunkd_access.log&lt;BR /&gt;
4.0K -rw-------  1 root root  110 May  6 17:09 splunkd_stderr.log&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:31 splunkd_stdout.log&lt;BR /&gt;
   0 -rw-------  1 root root    0 Apr 26 15:31 splunklogger.log&lt;BR /&gt;
 36K -rw-------  1 root root  33K Apr 26 15:36 web_access.log&lt;BR /&gt;
 20K -rw-------  1 root root  19K Apr 26 15:36 web_service.log  &lt;/P&gt;

&lt;P&gt;I don't care too much for these logs since I simply want light forwarder to forward system and application logs to my central log servers. &lt;/P&gt;

&lt;P&gt;Anyway to fix this?&lt;/P&gt;

&lt;P&gt;Let me know. &lt;/P&gt;

&lt;P&gt;Thanks. &lt;/P&gt;

&lt;P&gt;B&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 00:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13049#M204</guid>
      <dc:creator>balbano</dc:creator>
      <dc:date>2010-05-07T00:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Minimizing logging on Splunk Light Forwarder...</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13050#M205</link>
      <description>&lt;P&gt;You can tune the log levels and sizes in $SPLUNK_HOME/etc/log.cfg.  After editing this file, you will need to restart Splunk.&lt;/P&gt;

&lt;P&gt;The specific parameters you will want to edit are the maxFileSize and maxBackupIndex under each file type.&lt;/P&gt;

&lt;P&gt;I recommend you retain as much data as you can since this data is very useful for troubleshooting problems.   &lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 00:55:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13050#M205</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-05-07T00:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Minimizing logging on Splunk Light Forwarder...</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13051#M206</link>
      <description>&lt;P&gt;Additional info on this top is available here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/wiki/Community:MinimizingForwarderFootprint" rel="nofollow"&gt;http://www.splunk.com/wiki/Community:MinimizingForwarderFootprint&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2010 03:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Minimizing-logging-on-Splunk-Light-Forwarder/m-p/13051#M206</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-05-12T03:07:44Z</dc:date>
    </item>
  </channel>
</rss>

