<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarder Tail Fails in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121186#M25161</link>
    <description>&lt;P&gt;Yes.  The link is "/var/tmp/xxx/xxx.log -&amp;gt; /usr/xxx/yyy/AAA/work/xxx_aaa_99.log".  From what I understand, the target of the link, in this case "/usr/xxx/yyy/AAA/work/xxx_aaa_99.log", is somehow "processed" and there is a period of about 1.0 to 1.5 seconds where it doesn't exist.  But once the process is complete, everything functions correctly except the forwarder doesn't continue to tail the new file.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 16:56:24 GMT</pubDate>
    <dc:creator>OldManEd</dc:creator>
    <dc:date>2020-09-28T16:56:24Z</dc:date>
    <item>
      <title>Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121184#M25159</link>
      <description>&lt;P&gt;I have several forwarders that are release 4.3.2.  The issue is that the log files they are configured to send to my indexers periodically rotate.  For some reason Splunk will not send any more data when this happens.  But, if I restart the forwarder, data starts coming in with no problems.  The strange thing is that this only happens on some of the forwarders.&lt;/P&gt;

&lt;P&gt;File permissions were checked and found to be OK.&lt;/P&gt;

&lt;P&gt;The related errors in the splunkd.log file are;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-14-2014 08:00:08.608 -0600 ERROR TailingProcessor - Ignoring path due to: failed to open for checksum: '/var/tmp/xxx/xxx.log' (No such file or directory)

06-14-2014 08:00:09.911 -0600 ERROR TailingProcessor - Unable to resolve path for symlink: /var/tmp/xxx/xxx.log.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 16:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121184#M25159</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2014-06-26T16:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121185#M25160</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;06-14-2014 08:00:09.911 -0600 ERROR&lt;BR /&gt;
TailingProcessor - Unable to resolve&lt;BR /&gt;
path for &lt;STRONG&gt;symlink&lt;/STRONG&gt;:&lt;BR /&gt;
/var/tmp/xxx/xxx.log.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;can you actually resolve that symlink using ls?&lt;/P&gt;

&lt;P&gt;tail /path/to/symlink&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 17:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121185#M25160</guid>
      <dc:creator>abonuccelli_spl</dc:creator>
      <dc:date>2014-06-26T17:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121186#M25161</link>
      <description>&lt;P&gt;Yes.  The link is "/var/tmp/xxx/xxx.log -&amp;gt; /usr/xxx/yyy/AAA/work/xxx_aaa_99.log".  From what I understand, the target of the link, in this case "/usr/xxx/yyy/AAA/work/xxx_aaa_99.log", is somehow "processed" and there is a period of about 1.0 to 1.5 seconds where it doesn't exist.  But once the process is complete, everything functions correctly except the forwarder doesn't continue to tail the new file.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121186#M25161</guid>
      <dc:creator>OldManEd</dc:creator>
      <dc:date>2020-09-28T16:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121187#M25162</link>
      <description>&lt;P&gt;Splunk bugs go unreported (or undetected) often.  I suggest upgrading to a later version of the forwarder, at least version 4.3.4 or 5.0.7 to see if you still encounter the issue.  &lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 17:39:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121187#M25162</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2014-06-26T17:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121188#M25163</link>
      <description>&lt;P&gt;So I had the same issue. The fix was upping the permissions to the symlink. So check to see if the user for your splunk install can get to the full location and increase the permissions accordingly.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2015 15:51:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121188#M25163</guid>
      <dc:creator>scc00</dc:creator>
      <dc:date>2015-08-11T15:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121189#M25164</link>
      <description>&lt;P&gt;I am facing the same issue and my forwarder version is 4.2.6 and forwarder runs as root. Thinking of doing a clean re-install of forwarder. &lt;BR /&gt;
If anyone found any other solution. Kindly advise.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 17:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121189#M25164</guid>
      <dc:creator>kamaljagga</dc:creator>
      <dc:date>2019-08-09T17:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder Tail Fails</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121190#M25165</link>
      <description>&lt;P&gt;I have the same problem, but the version is not the problem, how can we resolve that plz ? &lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 09:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-Tail-Fails/m-p/121190#M25165</guid>
      <dc:creator>Kawtar</dc:creator>
      <dc:date>2019-08-19T09:46:12Z</dc:date>
    </item>
  </channel>
</rss>

