Getting Data In

How can I resolve Splunk input offset?

joe06031990
Communicator

Hi,

I am onboarding the /var/log/secure path and i am getting the bellow about offset 

INFO WatchedFile

/path/to/file.log

Will begin reading at offset=253 for file

Just wondered what I could do to resolve this?

 

Thanks,

Joe

Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

There is nothing you need to do.  The message is informational and is just Splunk telling you what it is doing.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is nothing you need to do.  The message is informational and is just Splunk telling you what it is doing.

---
If this reply helps you, Karma would be appreciated.
0 Karma

joe06031990
Communicator

Hi, I have two servers with identical server classes and apps one has onboard /var/log/secure and one has not, the one that has not has that message about the offset but the one which has doesn't have the offset message.

0 Karma
Get Updates on the Splunk Community!

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...