<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: getting file logs in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513858#M34298</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224919"&gt;@henrytran&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you have a Universal Forwarder on the server where files are stored, it reads the logs every 30 second (by default but it's configurable), so your files are read before they move.&lt;/P&gt;&lt;P&gt;So you don't need a script.&lt;/P&gt;&lt;P&gt;A script could help if your cannot install a UF on that server, but this isn't a Splunk question, it's a Linux question.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2020 08:42:07 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-08-13T08:42:07Z</dc:date>
    <item>
      <title>getting file logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513802#M34290</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am working on getting the logs into a dashboard. Files are sitting in the source a 2 minutes and will be moved to another server after 2 minutes time frame. my concern is if there is a script pull the logs within the time frame.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Henry&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 20:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513802#M34290</guid>
      <dc:creator>henrytran</dc:creator>
      <dc:date>2020-08-12T20:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: getting file logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513858#M34298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224919"&gt;@henrytran&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you have a Universal Forwarder on the server where files are stored, it reads the logs every 30 second (by default but it's configurable), so your files are read before they move.&lt;/P&gt;&lt;P&gt;So you don't need a script.&lt;/P&gt;&lt;P&gt;A script could help if your cannot install a UF on that server, but this isn't a Splunk question, it's a Linux question.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 08:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513858#M34298</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-13T08:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: getting file logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513950#M34308</link>
      <description>&lt;P&gt;I am clarifying that how quick the Universal Forwarder reads the files? because&amp;nbsp;I am concerning about 2 minutes limitation in reading 500 files or 50,000 files.&lt;/P&gt;&lt;P&gt;Thank you for responding to my questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Henry T&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 16:28:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513950#M34308</guid>
      <dc:creator>henrytran</dc:creator>
      <dc:date>2020-08-13T16:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: getting file logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513952#M34309</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224919"&gt;@henrytran&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I think that an UF can read 50,000 linea in 2.5 minutes, but to be sure, you can do a test.&lt;/P&gt;&lt;P&gt;If your UF is too slow, you can copy the files in another folder, use it for reading and delete files after, but I don't think that's necessary.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 17:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/513952#M34309</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-13T17:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: getting file logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/514149#M34335</link>
      <description>&lt;P&gt;I appreciate it for your responses.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 15:41:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/getting-file-logs/m-p/514149#M34335</guid>
      <dc:creator>henrytran</dc:creator>
      <dc:date>2020-08-14T15:41:45Z</dc:date>
    </item>
  </channel>
</rss>

