Deployment Architecture

Deletion of a log file being indexed by Splunk

madhavi_fmr
New Member

I have installed a forwarded on a machine and configure it to read some local log file.A Splunk indexer and a search machine is able to read the data.
In case if the log file is not available in the system, what happens ? If it gets deleted by some user,what will happen ?

Tags (1)
0 Karma

Cris
Explorer

Nothing happens! The forwarder continues to remain pending file.

0 Karma
Get Updates on the Splunk Community!

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...

Thank You for Celebrating CX Day with Splunk!

Yesterday the entire team at Splunk + Cisco joined the global celebration of CX Day - celebrating our ...