All Apps and Add-ons

Splunk stops reading new files in a directory when the old file is deleted

sun1000
Path Finder

We are monitoring docker container logs in base linux OS using universal forwarder, whenever docker containers gets restarted the old files will get deleted and new files/folders will get created. When that happens Splunk UF (7.2.3) stops reading new files. I think it is still looking for old file, how to handle this situation ?

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...