Archive

rotating sylog file

Explorer

Hi,

How is splunk dealing with logfiles which rotate like syslog ? Will splunk loose data during the rotation ?

To add some details. I assume Splunk checks on a regular basis if the logfile exists and reads new unindexed data from the logfile. If the logfile is rotated between the Splunk checks data get lost or ?

Markus

Tags (2)
0 Karma

Legend

No, it will not. See gkanapathy's answer to this (identical) question: http://splunk-base.splunk.com/answers/10309/log-file-rotation

Explorer

It answers one part of my question

0 Karma