Getting Data In

Why does Splunk 'lose interest' in files that are infrequently written to?

timrich66
Communicator

In our non-prod environment, some files are not written to on a regular basis.  In these cases the UF often needs to be restarted to start the ingestion of events.

The monitor stanza in use is very basic and does not have an 'ignoreOlderThan' value set.

Here is an example - 

[monitor:///my_non_prod_path/Log/app.log]
index=my_non_prod_index
sourcetype = nonprd_sourcetype
disabled=false

Are there global variables that would override this and cause events to not be ingested?

Thanks

 

Labels (2)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

there are so many reasons for not reading file using monitor input.

worth reading below:

https://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

there are so many reasons for not reading file using monitor input.

worth reading below:

https://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs

————————————
If this helps, give a like below.

timrich66
Communicator

Thanks for the link.  It makes interesting reading.  I have asked our unix SA to add debugging to the UF so I can get more details.

Events from different files on the server in question are being ingested and the same file name on a different server is also providing events.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...