<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with log rotation in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343096#M93641</link>
    <description>&lt;P&gt;What does your &lt;CODE&gt;monitor&lt;/CODE&gt; stanza look like, and how are you rotating (filename, compression, etc)?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2017 15:22:15 GMT</pubDate>
    <dc:creator>micahkemp</dc:creator>
    <dc:date>2017-12-12T15:22:15Z</dc:date>
    <item>
      <title>Issue with log rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343094#M93639</link>
      <description>&lt;P&gt;We have log files that are being monitored. Log files are deleted every 1 hour. We noticed that at the time of log rotation happens, some of the events are missed to indexed in splunk. How can I fix issue so that we don’t miss any data.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343094#M93639</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2017-12-12T15:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with log rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343095#M93640</link>
      <description>&lt;P&gt;Hi maniu1609,&lt;BR /&gt;
the easiest way (if possible) should be to rotate logs in a different file so you can read the last logs in the new file, after a few time (1 or 2 minutes) you can delete it, because the problem is that logs between the last Splunk ingestion and deletion (max 30 seconds) are missed.&lt;BR /&gt;
If it isn't possible you can reduce Forwarder read interval but anyway you lose something.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343095#M93640</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-12-12T15:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with log rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343096#M93641</link>
      <description>&lt;P&gt;What does your &lt;CODE&gt;monitor&lt;/CODE&gt; stanza look like, and how are you rotating (filename, compression, etc)?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343096#M93641</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-12T15:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with log rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343097#M93642</link>
      <description>&lt;P&gt;we have log file aaa.log and if the log file is older than 1hr, then file will be deleted. File monitor stanza just has index, sourcetype and host_regex details alone.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 08:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-log-rotation/m-p/343097#M93642</guid>
      <dc:creator>maniu1609</dc:creator>
      <dc:date>2017-12-13T08:34:16Z</dc:date>
    </item>
  </channel>
</rss>

