HI
in splunkd.log file I am seeing:
TailReader [260668 tailreader0] - Batch input finished reading file='/opt/splunkforwarder/var/spool/splunk/tracker.log'
and In splunk, I am seeing the logs as well
Basically, I want to know that is happening here.
this tracker.log file should be under index=_internal but somehow this file is present under index=linux and in Linux TA, I can see the [linux_audit] sourcetype config under props.conf.
who is calling this as I am not seeing any related input parameter for this.
Kind Regards,
Rashid