Getting Data In

Files can't be ingested while being in transit via ftp

danielbb
Motivator

The case at https://community.splunk.com/t5/Getting-Data-In/Issue-on-file-monitoring-using-forwader/m-p/478063#M... is similar.

When files are being ftp'ed to the location we see in _internal errors that the file can't be read. Comes the weekend and this host is being rebooted and the files are being ingested.

We looked at MonitorNoHandle that allows reading while the file is being written on Windows but MonitorNoHandle only allows one such file per stanza.

We asked the customer to ftp the files to another directory and move them later via a script but the customer wasn't thrilled about this idea.

We also thought that maybe there is a way to have the UF check for new files multiple times before putting them in the black list and it doesn't seem to be possible.

What can we do?

 

 

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...