<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144323#M29470</link>
    <description>&lt;P&gt;Thanks maciep,&lt;/P&gt;

&lt;P&gt;I am trying to get dual feeds from a windows box to 2 different splunk indexes. Could you please let me know if you have any approach to achieve the same apart from symbolic link. &lt;/P&gt;</description>
    <pubDate>Sun, 30 Sep 2018 23:15:16 GMT</pubDate>
    <dc:creator>RupeshMano</dc:creator>
    <dc:date>2018-09-30T23:15:16Z</dc:date>
    <item>
      <title>Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144318#M29465</link>
      <description>&lt;P&gt;We would like to consume the error log from our various SQL databases.  Our SQL team does not configure the databases to log in a common directory and there could be multiple logs in multiple drives on a server.  Instead of specifying all of the possible drives and resource intense recursive inputs, our SQL team tried creating a symlink for us. &lt;/P&gt;

&lt;P&gt;They could create a symlink to each log file and store all of those symlinks in one common directory.  Then we could just injest whatever is in that directory.&lt;/P&gt;

&lt;P&gt;What i'm noticing is that on a Splunk restart, the errorlog files are read fine, but updates to those log files are not seen by Splunk.  I'm just wondering if this is supposed to work as I think it should - as new data is written to target of those symlinks, splunk would realize the target file changed and consume the new log lines.  And if so, am I maybe missing a setting somewhere?  If it's not supposed to work or we can't get it to work, no big deal.  I know I have other options to specify the various paths in inputs.&lt;/P&gt;

&lt;P&gt;These servers are mix of Win 2003, 2008 and 2012.  Splunk forwarder version 6.2.1.  The symlinks are created under SQL_ERRORLOGS directory on the root of C:.  Monitoring stanza is below.  Any insight would be appreciated.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\SQL_ERRORLOGS]
index = upmc_sql
sourcetype = sql:error
disabled = false
followSymlink = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2015 13:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144318#M29465</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2015-04-15T13:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144319#M29466</link>
      <description>&lt;P&gt;I have exact same problem in the same version of forwarder. New files are not seen until the forwarder is restarted. the destination directory is a symlink to another local drive on the system. we already use crcSalt =  parameter.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 09:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144319#M29466</guid>
      <dc:creator>mic1024</dc:creator>
      <dc:date>2015-05-01T09:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144320#M29467</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am facing similar issue, does anyone had any solution to this ?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 02:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144320#M29467</guid>
      <dc:creator>RupeshMano</dc:creator>
      <dc:date>2018-09-27T02:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144321#M29468</link>
      <description>&lt;P&gt;we never got back to implementing this approach, so i don't know of a fix....but i haven't tried in a while either.  &lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 16:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144321#M29468</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2018-09-28T16:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144322#M29469</link>
      <description>&lt;P&gt;Thanks maciep,&lt;/P&gt;

&lt;P&gt;I am trying to get dual feeds from Windows box to 2 different indexes. Please let me know if you have any approach in achieving the same apart from symlink.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Sep 2018 23:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144322#M29469</guid>
      <dc:creator>RupeshMano</dc:creator>
      <dc:date>2018-09-30T23:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring symbolic links in a directory on Windows with Splunk 6.2.1, why are updates to log files not getting picked up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144323#M29470</link>
      <description>&lt;P&gt;Thanks maciep,&lt;/P&gt;

&lt;P&gt;I am trying to get dual feeds from a windows box to 2 different splunk indexes. Could you please let me know if you have any approach to achieve the same apart from symbolic link. &lt;/P&gt;</description>
      <pubDate>Sun, 30 Sep 2018 23:15:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-symbolic-links-in-a-directory-on-Windows-with-Splunk/m-p/144323#M29470</guid>
      <dc:creator>RupeshMano</dc:creator>
      <dc:date>2018-09-30T23:15:16Z</dc:date>
    </item>
  </channel>
</rss>

