Getting Data In

Universal Forwarder not sending previous logs

francisaugusto
New Member

Hi,

I am using Universal Forwarder  on a Mac configured to monitor a few log files. It is sending data fine, and it resumes sending data from those files after a disruption of the network.

The thing is, it is not sending the data written to the log files while the internet was off. Maybe it is caching the data elsewhere and not sending it? 

Reading the documentation, I see that there is no persistent queue for the monitor input. Does that mean that the forward won't pause the parsing of a log file when it can't reach the server?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...