Monitoring Splunk

monitoring log truncated

rjfv8205
Path Finder

We have a service where logs are truncated. Example, we have hola.log that fridays copy all content to new file hola20190306.log and hola.log is empty.

My question, if universal forwarder monitoring hola.log, send info from begin or from position of the last event before truncated? Lost some events?

Sorry my english is not very good

Thank you in advance

Tags (1)
0 Karma

jnahuelperez35
Path Finder

It always send information from the last line that was generated.
If universal forwarder is monitoring the file named "hola.log" will monitor every line that was generated, after being empty or at leats all the lines goes to new "hola.log"

EDiT: you will never lost logs. i leave you this link that can help you to understand best practices about log rotation https://answers.splunk.com/answers/577144/about-log-rotation-best-practices.html

Let me know if i answer your question.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...