<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Latest log not showing in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492015#M84105</link>
    <description>&lt;P&gt;I found a similar issue here : &lt;A href="https://answers.splunk.com/answers/680732/splunk-skips-or-delays-indexing-of-the-log-file-du.html" target="_blank"&gt;https://answers.splunk.com/answers/680732/splunk-skips-or-delays-indexing-of-the-log-file-du.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Made the change as specified :  time_before_close = 1&lt;/P&gt;

&lt;P&gt;But doesn't look like it helped. Forwarder version is 7.0.3&lt;/P&gt;

&lt;P&gt;Unless I need to wait until the log rolls again at midnight tonight?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 03:06:45 GMT</pubDate>
    <dc:creator>justindett</dc:creator>
    <dc:date>2020-09-30T03:06:45Z</dc:date>
    <item>
      <title>Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492014#M84104</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a weird issue where when a log rolls and a new log gets created, it takes about a day or so to actually show the new log in Splunk.  Looking  on the server, the new log exists. But Splunk is only showing the last log before the new one was created.&lt;/P&gt;

&lt;P&gt;Any idea why this would happen? &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 06:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492014#M84104</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2019-11-21T06:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492015#M84105</link>
      <description>&lt;P&gt;I found a similar issue here : &lt;A href="https://answers.splunk.com/answers/680732/splunk-skips-or-delays-indexing-of-the-log-file-du.html" target="_blank"&gt;https://answers.splunk.com/answers/680732/splunk-skips-or-delays-indexing-of-the-log-file-du.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Made the change as specified :  time_before_close = 1&lt;/P&gt;

&lt;P&gt;But doesn't look like it helped. Forwarder version is 7.0.3&lt;/P&gt;

&lt;P&gt;Unless I need to wait until the log rolls again at midnight tonight?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492015#M84105</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2020-09-30T03:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492016#M84106</link>
      <description>&lt;P&gt;Hi @justindett,&lt;/P&gt;

&lt;P&gt;Which files are you using for your input ? The original one or the rolled one ? &lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 13:24:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492016#M84106</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-11-21T13:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492017#M84107</link>
      <description>&lt;P&gt;Below is the content of the inputs.conf The whole log directory is specified, but its always just picked up the original .log file which is fine.&lt;/P&gt;

&lt;P&gt;[monitor:///WebSphere8/applications/dev/psiberworks/logs]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
whitelist = .log$&lt;/P&gt;

&lt;H1&gt;crcSalt = SOURCE&lt;/H1&gt;

&lt;P&gt;index = ibm_was_app_psi-was8-dev-01&lt;BR /&gt;
time_before_close = 1&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492017#M84107</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2020-09-30T03:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492018#M84108</link>
      <description>&lt;P&gt;What happens if your crcSalt is enabled ? do you still have the issue ? &lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 14:07:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492018#M84108</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-11-21T14:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492019#M84109</link>
      <description>&lt;P&gt;You probably have too many co-resident files.  At hundreds of files (whether or not Splunk is supposed to forward them or not, or whether it already has or not), things slow down (like you are seeing).  At thousands of files, things pretty much completely stop.  A good test is that if you get a significant surge just after restarting the forwarder and then it goes back to really, really slow, then this is your problem.  Do proper OS-level housekeeping to move/archive/delete older files and things will go back to snappy again.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 15:09:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492019#M84109</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-21T15:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492020#M84110</link>
      <description>&lt;P&gt;@woodcock There are only 30 logs in this directory. I have enabled the crcSalt now as well. Lets see if that makes a difference.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 16:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492020#M84110</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2019-11-21T16:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492021#M84111</link>
      <description>&lt;P&gt;That was going to be my suggestion(crcSalt).  How did it work out for you?&lt;/P&gt;

&lt;P&gt;When you say renamed, were there new log file names being created or were files moving to a new directory and the same log file being appended to but just new logs?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2019 01:52:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492021#M84111</guid>
      <dc:creator>Sahr_Lebbie</dc:creator>
      <dc:date>2019-11-23T01:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492022#M84112</link>
      <description>&lt;P&gt;Probably when the log rolls, the new log is created with the wrong &lt;CODE&gt;ownership&lt;/CODE&gt; or &lt;CODE&gt;permissions&lt;/CODE&gt; so that user &lt;CODE&gt;splunk&lt;/CODE&gt; cannot read it but then there is a housekeeping ( probably &lt;CODE&gt;cron&lt;/CODE&gt;-based) job that comes around once a day and deleted old files and fixes &lt;CODE&gt;ownership&lt;/CODE&gt; and &lt;CODE&gt;permissions&lt;/CODE&gt;.  This should be easy to check, just keep doing this until you see it rotate and look:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ls -altr /Your/Path/To/Files/Here
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 23 Nov 2019 16:43:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492022#M84112</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-23T16:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Latest log not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492023#M84113</link>
      <description>&lt;P&gt;Enabling the crcSalt seemed to have solved the issue. Logs seem to be up to date for the last couple days now.&lt;/P&gt;

&lt;P&gt;Thanks for all the suggestions &lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 06:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Latest-log-not-showing-in-Splunk/m-p/492023#M84113</guid>
      <dc:creator>justindett</dc:creator>
      <dc:date>2019-11-25T06:16:40Z</dc:date>
    </item>
  </channel>
</rss>

