Getting Data In

Splunk forwarder - When the log file will be send to splunk indexer ?

clementros
Path Finder

Hi,

I'm currently monitoring log files on unix server. Jobs application write log file in a directory.
I want to monitor only log file that is finished to be write. How i can do that ?

I don't want splunk to compare the beginning of the file to know if a file was already send to the indexer because if new lines are added to this file the forwarder will not see it.

If the forwarder compare last lines to see if a file is new, it will sent the same file multiple time rights ?

Can you help me please ?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

By default, forwarders read new lines from monitored files and send only the new data to indexers.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, forwarders read new lines from monitored files and send only the new data to indexers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

clementros
Path Finder

Thank you

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...