<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog files growing out of control. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85311#M17752</link>
    <description>&lt;P&gt;&lt;A href="http://linuxcommand.org/man_pages/logrotate8.html"&gt;logrotate&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2013 19:19:23 GMT</pubDate>
    <dc:creator>jonuwz</dc:creator>
    <dc:date>2013-04-04T19:19:23Z</dc:date>
    <item>
      <title>syslog files growing out of control.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85310#M17751</link>
      <description>&lt;P&gt;How do I deal with large syslog files that keep growing?&lt;BR /&gt;
Do I just delete them or is there an automated way of rolling them. I don't want to lose the data or disconnect the hosts sending it.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2013 19:08:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85310#M17751</guid>
      <dc:creator>craigrussell</dc:creator>
      <dc:date>2013-04-04T19:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: syslog files growing out of control.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85311#M17752</link>
      <description>&lt;P&gt;&lt;A href="http://linuxcommand.org/man_pages/logrotate8.html"&gt;logrotate&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2013 19:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85311#M17752</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2013-04-04T19:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: syslog files growing out of control.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85312#M17753</link>
      <description>&lt;P&gt;Thanks for the tip. I'll try it.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2013 15:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85312#M17753</guid>
      <dc:creator>craigrussell</dc:creator>
      <dc:date>2013-04-05T15:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: syslog files growing out of control.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85313#M17754</link>
      <description>&lt;P&gt;I agree with the answer above.&lt;/P&gt;

&lt;P&gt;Man Page:&lt;BR /&gt;
&lt;A href="http://linuxcommand.org/man_pages/logrotate8.html"&gt;http://linuxcommand.org/man_pages/logrotate8.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Tutorial Step-by-Step&lt;BR /&gt;
&lt;A href="http://www.thegeekstuff.com/2010/07/logrotate-examples/"&gt;http://www.thegeekstuff.com/2010/07/logrotate-examples/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2013 15:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85313#M17754</guid>
      <dc:creator>borisalves</dc:creator>
      <dc:date>2013-04-05T15:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: syslog files growing out of control.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85314#M17755</link>
      <description>&lt;P&gt;Note that in the Splunk context, you probably want the "delaycompress" option, so that rotated log files can be correctly identified, and read to the end of the file &lt;EM&gt;even&lt;/EM&gt; after the file has been rotated.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2013 16:45:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-files-growing-out-of-control/m-p/85314#M17755</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-04-05T16:45:58Z</dc:date>
    </item>
  </channel>
</rss>

