Getting Data In

Continuous monitoring doesn't work when the size of the file is constant

mzn1979
Explorer

 

Hi guys;

I want to monitor a single file with a universal forwarder. It works perfectly till the size of the file reaches 250 MB.

At that moment, when I open the file, new logs are there but the size of the file not change.

In this circumstance, Splunk UF can't sense the changes and send new logs to indexers, till I restart the UF!

So is there any configuration that I missed? or any suggestion to solve this problem.
 
Tanks in advance.
Labels (2)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...