Archive

Deletion of a log file being indexed by Splunk

New Member

I have installed a forwarded on a machine and configure it to read some local log file.A Splunk indexer and a search machine is able to read the data.
In case if the log file is not available in the system, what happens ? If it gets deleted by some user,what will happen ?

Tags (1)
0 Karma

Explorer

Nothing happens! The forwarder continues to remain pending file.

0 Karma