Getting Data In

Forwarder is not forwarding all the files in directory.

kmisaal
New Member

I have configured a forwarder on Linux and receiver on different Linux box.

After restarting the forwarder I can see only the latest file got forwarded and on receiver only one file is indexed.

However I can see on forwarder there are multiple files got indexed. The data input for forwarder is "monitor file and directory" with the path of logs directory.

This logs directory has multiple log files.

Please let me know why forwarder is not forwarding all the files.

Tags (1)
0 Karma

LCM
Contributor

Hard to guess what the problem could be since a part got forwarded though!

Can you investigate following:

  • in the directory you're monitoring: create a new "dummy" file wich consist eg. "Hello World" (does that work - is it being indexed - can you see it on the receiver box)
  • modify one of the existing file with a new entry
  • check splunkd.log
  • netstat -a (although that should work 😉 )
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...