<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gettin news data by Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Gettin-news-data-by-Universal-Forwarder/m-p/685162#M114319</link>
    <description>&lt;P&gt;Hello everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I turn to you because I have a little problem. I have an MFT server that generates logs in a directory. In this directory the log files are stored in directories that have the name of the day.&amp;nbsp;And the log files have the name 1000005847456.log. For example, today’s logs 23 April 2024 are stored in the 2024-04-23/ directory.&amp;nbsp;&amp;nbsp;For now, I have this input.conf file :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///data/logs/.../100000*.log]
disabled=false
sourcetype=log4j
host=PC
followTail=0
index=test_wild&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;When I launch the Universal Forwarder, it starts listing all files in/data/logs/.../ .&amp;nbsp;And it also starts to send the data in the log directory as of 4 days ago.&amp;nbsp;I am not looking to retrieve the old log data but the log data of today. I don’t understand this behavior of the Universal Forwarder. Could someone help me?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 15:03:06 GMT</pubDate>
    <dc:creator>michaelteck</dc:creator>
    <dc:date>2024-04-23T15:03:06Z</dc:date>
    <item>
      <title>Gettin news data by Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Gettin-news-data-by-Universal-Forwarder/m-p/685162#M114319</link>
      <description>&lt;P&gt;Hello everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I turn to you because I have a little problem. I have an MFT server that generates logs in a directory. In this directory the log files are stored in directories that have the name of the day.&amp;nbsp;And the log files have the name 1000005847456.log. For example, today’s logs 23 April 2024 are stored in the 2024-04-23/ directory.&amp;nbsp;&amp;nbsp;For now, I have this input.conf file :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///data/logs/.../100000*.log]
disabled=false
sourcetype=log4j
host=PC
followTail=0
index=test_wild&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;When I launch the Universal Forwarder, it starts listing all files in/data/logs/.../ .&amp;nbsp;And it also starts to send the data in the log directory as of 4 days ago.&amp;nbsp;I am not looking to retrieve the old log data but the log data of today. I don’t understand this behavior of the Universal Forwarder. Could someone help me?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 15:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Gettin-news-data-by-Universal-Forwarder/m-p/685162#M114319</guid>
      <dc:creator>michaelteck</dc:creator>
      <dc:date>2024-04-23T15:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Gettin news data by Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Gettin-news-data-by-Universal-Forwarder/m-p/685164#M114320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263859"&gt;@michaelteck&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you give to the monitor command a path, Splunk reads all the file in this path.&lt;/P&gt;&lt;P&gt;You can exclude events older than a data (e.g. 1 day ago), adding a parameter to the input stanza&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ignoreOlderThan = 1d&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 15:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Gettin-news-data-by-Universal-Forwarder/m-p/685164#M114320</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-04-23T15:12:40Z</dc:date>
    </item>
  </channel>
</rss>

