Splunk Enterprise
Version:8.1.3
Hi All
Can Splunk Enterprise Version:8.1.3 handle circular log?
What I'm taking out of you answer is a "no".
Splunk can NOT handle circular logs.
It depends on how you define "handle". Splunk expects a file it is monitoring to have new data added to the end. If the start of the file is overwritten then Splunk assumes the whole file is new and will re-ingest it, resulting in duplicate data. But the file is still handled!
What I'm taking out of you answer is a "no".
Splunk can NOT handle circular logs.