Getting Data In

Monitoring Log File provided as - Days of Week and Hourly

pjohnson1
Path Finder

We are provided a certain type of log in the following format:

App-Hourly.log
App-Mon.log
App-Tue.log
App-Wed.log
App-Thur.log
App-Fri.log
App-Sat.log
App-Sun.log

The 'Hourly' log is rotated hourly and 'Days of the Week' are rotated daily.

What would be the best way to feed these logs into Splunk from the Forwarder without duplicating events?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

So... each event is written once to App-Hourly.log and once to App-$weekday$.log?

I'd monitor all seven Day-of-Week files from the forwarder and have the app people disable the duplicate hourly log entirely.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...