<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [RESOLVED] Forwarder stops at midnight on Windows 2012R2 DHCP server log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/RESOLVED-Forwarder-stops-at-midnight-on-Windows-2012R2-DHCP/m-p/127979#M26284</link>
    <description>&lt;P&gt;Well, my monitor stanza actually did work.&lt;/P&gt;

&lt;P&gt;I guess I wasn't patient enough after I put in "&lt;STRONG&gt;alwaysOpenFile = 1&lt;/STRONG&gt;", which I believe is what made Splunk deal with the log file rotation correctly, in combination with "&lt;STRONG&gt;initCrcLength = 2000&lt;/STRONG&gt;".&lt;/P&gt;

&lt;P&gt;I don't believe that "*&lt;EM&gt;crcSalt = *&lt;/EM&gt;" is needed in this case but I am not going to change the stanza at this point as that does no harm either.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2015 13:29:03 GMT</pubDate>
    <dc:creator>ww9rivers</dc:creator>
    <dc:date>2015-02-12T13:29:03Z</dc:date>
    <item>
      <title>[RESOLVED] Forwarder stops at midnight on Windows 2012R2 DHCP server log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/RESOLVED-Forwarder-stops-at-midnight-on-Windows-2012R2-DHCP/m-p/127978#M26283</link>
      <description>&lt;P&gt;I have Splunk Universal Forwarders on 4 Windows 2012R2 servers, monitoring the DHCP server logs with this stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://Z:\dhcp\logs]
disabled = 0
sourcetype = DhcpSrvLog
whitelist = DhcpSrvLog*
crcSalt = &amp;lt;SOURCE&amp;gt;
initCrcLength = 2000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That works when I started the forwarder. But I found that the forwarder stopped sending new logs to my indexers at midnight sharp, which I don't know if it has something to do with the fact that the log for today has a timestamp of midnight yesterday:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Mode                LastWriteTime     Length Name
----                -------------     ------ ----
-a---          2/4/2015  12:00 AM  146695986 DhcpSrvLog-Tue.log
-a---          2/4/2015  12:00 AM  138881102 DhcpSrvLog-Wed.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;At that point, I added an "alwaysOpenFile = 1" item in the stanza to see if that solves the problem. But I came in this morning to find that it had changed nothing whatsoever.&lt;/P&gt;

&lt;P&gt;Soooo, what else can I do to handle this Microsoft beast?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[Edit]&lt;/STRONG&gt;: Not sure if (or how) this could be a factor: The folder in the monitor stanza "Z:/dhcp/logs" is a Windows symbolic link to a folder "E:/dhcp/logs_&amp;lt;&lt;EM&gt;HOSTNAME&lt;/EM&gt;&amp;gt;" -- those forward slashes (/) are replacement of back slashes in Windows, of course.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2015 14:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/RESOLVED-Forwarder-stops-at-midnight-on-Windows-2012R2-DHCP/m-p/127978#M26283</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2015-02-05T14:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: [RESOLVED] Forwarder stops at midnight on Windows 2012R2 DHCP server log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/RESOLVED-Forwarder-stops-at-midnight-on-Windows-2012R2-DHCP/m-p/127979#M26284</link>
      <description>&lt;P&gt;Well, my monitor stanza actually did work.&lt;/P&gt;

&lt;P&gt;I guess I wasn't patient enough after I put in "&lt;STRONG&gt;alwaysOpenFile = 1&lt;/STRONG&gt;", which I believe is what made Splunk deal with the log file rotation correctly, in combination with "&lt;STRONG&gt;initCrcLength = 2000&lt;/STRONG&gt;".&lt;/P&gt;

&lt;P&gt;I don't believe that "*&lt;EM&gt;crcSalt = *&lt;/EM&gt;" is needed in this case but I am not going to change the stanza at this point as that does no harm either.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 13:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/RESOLVED-Forwarder-stops-at-midnight-on-Windows-2012R2-DHCP/m-p/127979#M26284</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2015-02-12T13:29:03Z</dc:date>
    </item>
  </channel>
</rss>

