Getting Data In

Why is my application log not getting created after we installed a universal forwarder?

Abilan1
Path Finder

Hi ,

We have installed one third party tool in our server and we wanted to forward those tool logs to a Splunk indexer, so we have configured universal forwarder in that machine and it is forwarding the logs to indexer without any issues. We have configured in that tool so that after the log size grown it to 10 MB, it renames this log file and creates a new log file with that same name. But what we noticed is after we installed universal forwarder, once the log size is grown it to 10 MB, my tool is renaming the log file and it is not creating the new log file. Not sure why it is behaving like this? We never faced this issue before, please help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Try logrotate, or talk to the vendor of that third-party tool failing to rotate its logs properly.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...