Getting Data In

Can I monitor a log from Aug 2022 if I installed a UF in Feb 2023?

blbr123
Path Finder

Hi All

I have one query with regards to Log Monitoring

Let's say I want to monitor abc.log and the last Updated date of the Log File is Aug 2022 or Sep 2022 and I install the UF in the Log server in Feb 2023 and create inputs monitoring for abc.log

Does splunk monitor the old data which is already there in the Log file from Aug or Sep 2022 and show the Logs in Splunk?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @blbr123,

in general it's possible, it depends on two factors:

  • if you still have the logs of august or september 2022 on your file system,
  • if you don't configure limits in the old logs acquisition.

The first condition is obvious.

The second condition is the default in log acquisision, but you could also put limits for old logs.

Obviously, you have to put them in an index with a retention greater than six months otherwise logs will be deleted few time after indexing.

Ciao.

Giuseppe

0 Karma

blbr123
Path Finder

In the first condition how can splunk check months old logs 

I didn't understand the second condition can you please explain clearly what does limits have to do with reading old logs?

0 Karma

blbr123
Path Finder

In the first condition how can splunk check months old logs 

I didn't understand the second condition can you please explain clearly what does limits have to do with reading old logs?

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @blbr123m,

Splunk can read all logs, stored in text files, even if of many months ago assigning to them the correct timestamp.

About the second condition: in Splunk inputs you can define a limit in the past to avoid to index too old logs, (e.g. index logs not older than 2 days) but by default there isn't any limit.

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...