Q: Is there a simple solution that would enable Splunk to index log file changes on Windows 2008 as they happen?
An application that writes text log files has recently been moved from Windows 2003 to (64 bit) Windows 2008 and we have been retesting it. Microsoft appear to have changed the behaviour of the file system descriptors.
On Windows 2003, Splunk 5.0.2 had been monitoring these log files and indexing log file data lines as they changed.
On Windows 2008, while the Log File Size increases, the modification date+time is remaining unchanged until the text log file closes (at end of day). Splunk 5.0.2 is no longer able to index log file changes as they happen, but only when the file is closed by the application - and at which point the modification date is updated.