Getting Data In

Issue with log rotation

maniu1609
Path Finder

We have log files that are being monitored. Log files are deleted every 1 hour. We noticed that at the time of log rotation happens, some of the events are missed to indexed in splunk. How can I fix issue so that we don’t miss any data.

0 Karma

micahkemp
Champion

What does your monitor stanza look like, and how are you rotating (filename, compression, etc)?

0 Karma

maniu1609
Path Finder

we have log file aaa.log and if the log file is older than 1hr, then file will be deleted. File monitor stanza just has index, sourcetype and host_regex details alone.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi maniu1609,
the easiest way (if possible) should be to rotate logs in a different file so you can read the last logs in the new file, after a few time (1 or 2 minutes) you can delete it, because the problem is that logs between the last Splunk ingestion and deletion (max 30 seconds) are missed.
If it isn't possible you can reduce Forwarder read interval but anyway you lose something.

Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...