<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding a Log File and Monitor Any Updates to that Log File in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37817#M6941</link>
    <description>&lt;P&gt;I added [monitor:///var/log/logmessages] to the inputs.conf file. logmessages is the file where my logs are written to.  Will this work?  &lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2011 00:04:35 GMT</pubDate>
    <dc:creator>ericmoss</dc:creator>
    <dc:date>2011-02-04T00:04:35Z</dc:date>
    <item>
      <title>Forwarding a Log File and Monitor Any Updates to that Log File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37815#M6939</link>
      <description>&lt;P&gt;I have a Linux server and a Windows server. My Windows server is the receiver and my Linux server is a forwarder.  There is a specific log file that contains the logs I want to forward to Windows server.  How do I do that?&lt;/P&gt;

&lt;P&gt;The most important thing I would like to do is monitor that log file for any logs that get written to it.  I do not want to keep uploading and forwarding that file as it grows to my Windows server.  So any log that gets generated, I want to forward that to the Windows server rather than the whole file.&lt;/P&gt;

&lt;P&gt;Any help is greatly appreciated.  Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2011 05:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37815#M6939</guid>
      <dc:creator>ericmoss</dc:creator>
      <dc:date>2011-02-03T05:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding a Log File and Monitor Any Updates to that Log File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37816#M6940</link>
      <description>&lt;P&gt;Looks like you are looking for basic Splunk forwarding and receiving functionality.  I suggest you start with the following from the docs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Enableforwardingandreceiving" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Enableforwardingandreceiving&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;BTW, splunk forwards the whole file the first time a new file is found (or when it's first setup as a &lt;CODE&gt;monitor&lt;/CODE&gt; input), then after that only newly added log events are forwarded.  Splunk doesn't keep re-copying the same file over and over again; if that's what you are asking about.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2011 05:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37816#M6940</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2011-02-03T05:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding a Log File and Monitor Any Updates to that Log File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37817#M6941</link>
      <description>&lt;P&gt;I added [monitor:///var/log/logmessages] to the inputs.conf file. logmessages is the file where my logs are written to.  Will this work?  &lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2011 00:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-a-Log-File-and-Monitor-Any-Updates-to-that-Log-File/m-p/37817#M6941</guid>
      <dc:creator>ericmoss</dc:creator>
      <dc:date>2011-02-04T00:04:35Z</dc:date>
    </item>
  </channel>
</rss>

