Getting Data In

Continuous monitoring doesn't work when the size of the file is constant

mzn1979
Explorer

 

Hi guys;

I want to monitor a single file with a universal forwarder. It works perfectly till the size of the file reaches 250 MB.

At that moment, when I open the file, new logs are there but the size of the file not change.

In this circumstance, Splunk UF can't sense the changes and send new logs to indexers, till I restart the UF!

So is there any configuration that I missed? or any suggestion to solve this problem.
 
Tanks in advance.
Labels (2)
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...