<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Log File Monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570210#M101065</link>
    <description>&lt;P&gt;Most probably&amp;nbsp;&lt;SPAN&gt;ignoreOlderthan is the culprit here. Splunk may have got restarted and found the file to be older than 5 days and ignored it (put it in the "ignored" list). It'll stay ignored even after new data is being added. Only restart will make it re-evaluated its file monitoring list and data got ingested.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the data is updated once every 7 days, keep your&amp;nbsp;ignoreOlderthan match that.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What kind of updates does the file get, new data gets appended OR it's completed re-written?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Oct 2021 12:41:49 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2021-10-08T12:41:49Z</dc:date>
    <item>
      <title>Splunk Log File Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570202#M101063</link>
      <description>&lt;P&gt;Hi Folks,&lt;BR /&gt;&lt;BR /&gt;We have log file monitoring of one of the text file , and that text file getting updated once in a week. Then Splunk reads the data from that file.&lt;BR /&gt;&lt;BR /&gt;Today we had faced a situation , where log file updated with todays data but not logs were sent to Splunk.&lt;BR /&gt;&lt;BR /&gt;we verified in splunkd.log and didn't find any info related to that specific log file, and Splunk UF connected to HF and everything&amp;nbsp; is working fine and other data was flowing to Splunk as usal.&lt;BR /&gt;&lt;BR /&gt;However after Splunk restart data sent to splunk,&lt;BR /&gt;&lt;BR /&gt;I was wondering if log file is not getting updated for some time , will Splunk ignores the file from monitoring until restart?.&lt;BR /&gt;&lt;BR /&gt;and we have stanza ignoreOlderthan set to 5d , is this something to do with&amp;gt; .&lt;BR /&gt;&lt;BR /&gt;we are aware that ignoreOlderthan used to lgnore logs data older than specified&amp;nbsp; time, just wanted to make sure this is not that case.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 11:59:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570202#M101063</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2021-10-08T11:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Log File Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570210#M101065</link>
      <description>&lt;P&gt;Most probably&amp;nbsp;&lt;SPAN&gt;ignoreOlderthan is the culprit here. Splunk may have got restarted and found the file to be older than 5 days and ignored it (put it in the "ignored" list). It'll stay ignored even after new data is being added. Only restart will make it re-evaluated its file monitoring list and data got ingested.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the data is updated once every 7 days, keep your&amp;nbsp;ignoreOlderthan match that.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What kind of updates does the file get, new data gets appended OR it's completed re-written?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 12:41:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570210#M101065</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-10-08T12:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Log File Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570381#M101087</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your explanation. will increase&amp;nbsp;&lt;STRONG&gt;ignoreOlderthan &lt;/STRONG&gt;time to match with thelog time update.&lt;BR /&gt;&lt;BR /&gt;regarding your question about log file update , each time log file will be updated with new data , replacing old data in file.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Oct 2021 09:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Log-File-Monitoring/m-p/570381#M101087</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2021-10-10T09:24:45Z</dc:date>
    </item>
  </channel>
</rss>

