<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 6.6.1 stops monitoring files in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361844#M5252</link>
    <description>&lt;P&gt;You should upgrade. There are known bugs for tailing files in versions this old.&lt;/P&gt;</description>
    <pubDate>Sat, 26 Jan 2019 03:14:03 GMT</pubDate>
    <dc:creator>davpx</dc:creator>
    <dc:date>2019-01-26T03:14:03Z</dc:date>
    <item>
      <title>Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361835#M5243</link>
      <description>&lt;P&gt;Recently updating from 6.5.3 to 6.6.1, I started running into a situation where at least one of my Heavy Forwarders would intermittently stop sending data.  The Heavy Forwarder is on a RedHat 6.x system, virtualized, with the latest patches.&lt;/P&gt;

&lt;P&gt;After reading some answers, I found the command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./bin/splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which for at least one of the files output the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;s:key name="/var/log/aruba/controller1.log"&amp;gt;
  &amp;lt;s:dict&amp;gt;
    &amp;lt;s:key name="file position"&amp;gt;22440152&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="file size"&amp;gt;20726882&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="parent"&amp;gt;/var/log/aruba/*.log&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="percent"&amp;gt;108.27&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="type"&amp;gt;open file&amp;lt;/s:key&amp;gt;
  &amp;lt;/s:dict&amp;gt;
&amp;lt;/s:key&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I figure it being over 100% read is odd.  When it got into this state, I checked the metrics in _internal for this monitored file and they had stopped recording.  With RedHat, I use 'logrotate', running on an hourly schedule.  The change from the file being read to stopping seems to have occurred on the hour.  It would stop working for 1-3 hours, then suddenly start reading again all by itself.  It's worked before with 6.5.3, but not with 6.6.1.  I downgraded last night to 6.5.3 on this one Heavy Forwarder, and it's back to working again, so I've eliminated logrotate and other OS patches.&lt;/P&gt;

&lt;P&gt;Can anyone advise on some other things to try with 6.6.1 to see if there's some new setting I should be using?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 17:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361835#M5243</guid>
      <dc:creator>craigkleen</dc:creator>
      <dc:date>2017-06-22T17:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361836#M5244</link>
      <description>&lt;P&gt;Definitely open a support case and add the &lt;CODE&gt;bug&lt;/CODE&gt; tag to this question.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 17:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361836#M5244</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-22T17:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361837#M5245</link>
      <description>&lt;P&gt;Will do. Thx&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 18:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361837#M5245</guid>
      <dc:creator>craigkleen</dc:creator>
      <dc:date>2017-06-22T18:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361838#M5246</link>
      <description>&lt;P&gt;Did a case get opened on this? I think I am seeing the same thing, and we can open one also.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2017 20:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361838#M5246</guid>
      <dc:creator>delink</dc:creator>
      <dc:date>2017-06-27T20:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361839#M5247</link>
      <description>&lt;P&gt;I have, and submitted a diag.  Waiting to hear back.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2017 23:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361839#M5247</guid>
      <dc:creator>craigkleen</dc:creator>
      <dc:date>2017-06-27T23:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361840#M5248</link>
      <description>&lt;P&gt;I think I have the same problem, or at least so similar it might as well be the same.  &lt;/P&gt;

&lt;P&gt;I have a CentOS 6.x HF that receives data via rsyslog and writes that data to different dated files based on filters.  So logs from routers would be saved in a file called yyyy-mm-dd-rtrs.log.  After I upgraded on Sept 9, all those feeds stopped (and more annoying, all my alerts for missing data didn't work... argh).  All files labeled 2017-09-08-xxx.log are indexed.  All files labeled 2017-09-09-xxx.log and later are not.&lt;/P&gt;

&lt;P&gt;Please keep us updated on this issue.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 12:40:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361840#M5248</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2017-09-14T12:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361841#M5249</link>
      <description>&lt;P&gt;We do have a case open with Splunk on this, and it is a noted bug now. My customer was running the case with support, so I do not have the JIRA for it, but they did offer a hotfix, so I think this may be fixed in either 6.6.3 or whenever 6.6.4 comes out.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 13:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361841#M5249</guid>
      <dc:creator>delink</dc:creator>
      <dc:date>2017-09-14T13:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361842#M5250</link>
      <description>&lt;P&gt;What was the final resolution on this from support, @craigkleen?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 04:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361842#M5250</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-11-18T04:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361843#M5251</link>
      <description>&lt;P&gt;Sorry for the delay.  Splunk's response wasn't great.  I basically had to write a "restart" into my log rotation script.  It might be fixed with the 7.x series now, but I haven't had the time to go back and check.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jan 2019 00:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361843#M5251</guid>
      <dc:creator>craigkleen</dc:creator>
      <dc:date>2019-01-19T00:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6.6.1 stops monitoring files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361844#M5252</link>
      <description>&lt;P&gt;You should upgrade. There are known bugs for tailing files in versions this old.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 03:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-6-6-1-stops-monitoring-files/m-p/361844#M5252</guid>
      <dc:creator>davpx</dc:creator>
      <dc:date>2019-01-26T03:14:03Z</dc:date>
    </item>
  </channel>
</rss>

