<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Frequency lea updates pointer file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Frequency-lea-updates-pointer-file/m-p/77857#M181583</link>
    <description>&lt;P&gt;Answering my own post here. &lt;BR /&gt;
From what I can tell, the &lt;EM&gt;lea_log_rec_num.cache&lt;/EM&gt; file only gets updated upon completion of the script run, meaning, the lea-connector has reached the end of the Checkpoint log file.&lt;/P&gt;

&lt;P&gt;Therefore, in a high-volume environment, it could take a long time for this script to finish its initial run.  &lt;/P&gt;

&lt;P&gt;Sean&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:26:31 GMT</pubDate>
    <dc:creator>sdwilkerson</dc:creator>
    <dc:date>2020-09-28T11:26:31Z</dc:date>
    <item>
      <title>Frequency lea updates pointer file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Frequency-lea-updates-pointer-file/m-p/77856#M181582</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Does anyone know the frequency that the lea-loggrabber-splunk app's lea_loggrabber process should write to its record-number cache &lt;EM&gt;lea_log_rec_num.cache&lt;/EM&gt;?&lt;/P&gt;

&lt;P&gt;It seems that when Splunk is restarted or if lea_loggrabber is HUPd that this pointer file is not written to so next time the process starts, it gets lots of old data.&lt;/P&gt;

&lt;P&gt;Also, a side note, is that because this pointer file is written to locally, you CANNOT use Splunk's Deployment Server to push this app since it will over write this record at each deployment/restart.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Sean&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Frequency-lea-updates-pointer-file/m-p/77856#M181582</guid>
      <dc:creator>sdwilkerson</dc:creator>
      <dc:date>2020-09-28T11:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Frequency lea updates pointer file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Frequency-lea-updates-pointer-file/m-p/77857#M181583</link>
      <description>&lt;P&gt;Answering my own post here. &lt;BR /&gt;
From what I can tell, the &lt;EM&gt;lea_log_rec_num.cache&lt;/EM&gt; file only gets updated upon completion of the script run, meaning, the lea-connector has reached the end of the Checkpoint log file.&lt;/P&gt;

&lt;P&gt;Therefore, in a high-volume environment, it could take a long time for this script to finish its initial run.  &lt;/P&gt;

&lt;P&gt;Sean&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Frequency-lea-updates-pointer-file/m-p/77857#M181583</guid>
      <dc:creator>sdwilkerson</dc:creator>
      <dc:date>2020-09-28T11:26:31Z</dc:date>
    </item>
  </channel>
</rss>

