Getting Data In

Monitoring Log File provided as - Days of Week and Hourly

pjohnson1
Path Finder

We are provided a certain type of log in the following format:

App-Hourly.log
App-Mon.log
App-Tue.log
App-Wed.log
App-Thur.log
App-Fri.log
App-Sat.log
App-Sun.log

The 'Hourly' log is rotated hourly and 'Days of the Week' are rotated daily.

What would be the best way to feed these logs into Splunk from the Forwarder without duplicating events?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

So... each event is written once to App-Hourly.log and once to App-$weekday$.log?

I'd monitor all seven Day-of-Week files from the forwarder and have the app people disable the duplicate hourly log entirely.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...