Getting Data In

Why is a specific log file not getting forwarded when others in the same directory do?

BT_Neophyte
Explorer

I'm having an issue where a specific log file is not forwarding, but others in the same directory and Splunk app are forwarding.

The files in question are:
server.log
server.log.0

The .0 is just where the server.log rolls over to so I don't care about forwarding that as it is just stale and duplicate data. I have created an inputs.conf file for this directory and simplified it just monitor "server*".

My issue is that server.log.0 is showing up in Splunk whereas server.log is NOT. If I change the inputs .conf to specifically look for server.log then nothing shows up in Splunk.

Both files have the same owner and read/write permissions. What could be causing this? It seems like all variables are equal but I'm getting different results.

Here is the inputs.conf file in question:
[monitor:///api/logs/server.log]
sourcetype=serverapi_logs
index=api

[monitor:///api/logs/error.log]
sourcetype=errorrapi_logs
index=api

And an ls on the directory:
error.log error.log.0 README.md server.log server.log.0

0 Karma

masonmorales
Influencer

Try restarting your splunk forwarder to see if it picks up server.log. If that doesn't help, grep for server.log in $SPUNK_HOME/var/log/splunk/splunkd.log and see if there are any errors.

0 Karma

masonmorales
Influencer

Could you post your inputs.conf please?

0 Karma

BT_Neophyte
Explorer

Added more info above

0 Karma

juvetm
Communicator

were you Specify the new source type in forwarder inputs

0 Karma

juvetm
Communicator

the problem is not the permission

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...