Hi guys;
I want to monitor a single file with a universal forwarder. It works perfectly till the size of the file reaches 250 MB.
At that moment, when I open the file, new logs are there but the size of the file not change.
In this circumstance, Splunk UF can't sense the changes and send new logs to indexers, till I restart the UF!
So is there any configuration that I missed? or any suggestion to solve this problem.