<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302984#M57217</link>
    <description>&lt;P&gt;Hi dantimola,&lt;BR /&gt;
no, If you change some log file you can continue to use your UF without restarting it.&lt;BR /&gt;
 you need to restart Splunk Universal Forwarder only if you change some .conf file.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2017 07:53:31 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-07-11T07:53:31Z</dc:date>
    <item>
      <title>Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302983#M57216</link>
      <description>&lt;P&gt;Hello fellow ninjas,&lt;/P&gt;

&lt;P&gt;Good day. I'd like to ask if splunk uf restart is essential after I deleted a log file that is being monitored by splunk? Because, every time I delete the file, splunk is still reading it resulting high resources usage.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3187i2863ECA68B27C3A4/image-size/large?v=v2&amp;amp;px=999" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Dan&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 06:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302983#M57216</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-07-11T06:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302984#M57217</link>
      <description>&lt;P&gt;Hi dantimola,&lt;BR /&gt;
no, If you change some log file you can continue to use your UF without restarting it.&lt;BR /&gt;
 you need to restart Splunk Universal Forwarder only if you change some .conf file.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 07:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302984#M57217</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-07-11T07:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302985#M57218</link>
      <description>&lt;P&gt;which version of SplunkUF you using? it might be a bug sometimes&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 08:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302985#M57218</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-07-11T08:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302986#M57219</link>
      <description>&lt;P&gt;Thanks for your answer. My case is that, even we deleted the log file, splunk is still reading it as seen on the screenshot I've provided. What could be the problem? &lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 03:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302986#M57219</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-07-12T03:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302987#M57220</link>
      <description>&lt;P&gt;Hi, its universal forwarder 6.2.6 and 6.4.0&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 03:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302987#M57220</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-07-12T03:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302988#M57221</link>
      <description>&lt;P&gt;Hi dantimola,&lt;BR /&gt;
until you don't disable it, Splunk input is waiting for a new file or variation of it.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 07:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302988#M57221</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-07-13T07:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it essential to restart splunk universal forwarder after deletion of monitored logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302989#M57222</link>
      <description>&lt;P&gt;I saw migration.conf in the uf. Is it possible that it was the culprit why the issue is occuring?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 03:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-essential-to-restart-splunk-universal-forwarder-after/m-p/302989#M57222</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-07-25T03:41:13Z</dc:date>
    </item>
  </channel>
</rss>

