Getting Data In

Universal Forwarder not sending previous logs

francisaugusto
New Member

Hi,

I am using Universal Forwarder  on a Mac configured to monitor a few log files. It is sending data fine, and it resumes sending data from those files after a disruption of the network.

The thing is, it is not sending the data written to the log files while the internet was off. Maybe it is caching the data elsewhere and not sending it? 

Reading the documentation, I see that there is no persistent queue for the monitor input. Does that mean that the forward won't pause the parsing of a log file when it can't reach the server?

Labels (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...