<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reading database logs from linux server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/508629#M86527</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222217"&gt;@islam&lt;/a&gt;&amp;nbsp;If the solution helps you, then an upvote would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jul 2020 22:09:34 GMT</pubDate>
    <dc:creator>venkateshparank</dc:creator>
    <dc:date>2020-07-11T22:09:34Z</dc:date>
    <item>
      <title>Reading database logs from linux server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/503909#M85936</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We want to read the database logs from a linux server, and the logs are stored in specific path “&amp;lt;/path&amp;gt;/log/” as example . The logs are archived at the end of every day in same directory of real time log file. The real time info writes into “vertica.log” file, so &lt;U&gt;we don’t want&lt;/U&gt; to read logs from the file “vertica.log”&lt;/P&gt;&lt;P&gt;How can we reed this archived&amp;nbsp; files in splunk.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vertica.log.png" style="width: 398px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9128iA9E0E105DDABEFA7/image-size/large?v=v2&amp;amp;px=999" role="button" title="vertica.log.png" alt="vertica.log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 12:19:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/503909#M85936</guid>
      <dc:creator>islam</dc:creator>
      <dc:date>2020-06-11T12:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Reading database logs from linux server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/504022#M85945</link>
      <description>&lt;P&gt;Create monitoring stanza like below:&lt;/P&gt;&lt;P&gt;[monitor:///&amp;lt;path&amp;gt;/log/vertica.log-*]&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;disabled = 0 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;crcSalt = &amp;lt;SOURCE&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index = &amp;lt;IndexName&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you still see the vertica.log is reading, trying adding below line in above Stanza&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;blacklist = vertica.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That would be like below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[monitor:///&amp;lt;path&amp;gt;/log/vertica.log-*]&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;disabled = 0 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;crcSalt = &amp;lt;SOURCE&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index = &amp;lt;IndexName&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;blacklist = vertica.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 22:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/504022#M85945</guid>
      <dc:creator>venkateshparank</dc:creator>
      <dc:date>2020-06-11T22:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Reading database logs from linux server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/508627#M86526</link>
      <description>&lt;P&gt;thanks a lot for your kindly reply.&lt;/P&gt;&lt;P&gt;we tried this solution&amp;nbsp; and we start receiving logs now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 21:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/508627#M86526</guid>
      <dc:creator>islam</dc:creator>
      <dc:date>2020-07-11T21:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Reading database logs from linux server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/508629#M86527</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222217"&gt;@islam&lt;/a&gt;&amp;nbsp;If the solution helps you, then an upvote would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 22:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-database-logs-from-linux-server/m-p/508629#M86527</guid>
      <dc:creator>venkateshparank</dc:creator>
      <dc:date>2020-07-11T22:09:34Z</dc:date>
    </item>
  </channel>
</rss>

