Getting Data In

Why is my application log not getting created after we installed a universal forwarder?

Abilan1
Path Finder

Hi ,

We have installed one third party tool in our server and we wanted to forward those tool logs to a Splunk indexer, so we have configured universal forwarder in that machine and it is forwarding the logs to indexer without any issues. We have configured in that tool so that after the log size grown it to 10 MB, it renames this log file and creates a new log file with that same name. But what we noticed is after we installed universal forwarder, once the log size is grown it to 10 MB, my tool is renaming the log file and it is not creating the new log file. Not sure why it is behaving like this? We never faced this issue before, please help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Try logrotate, or talk to the vendor of that third-party tool failing to rotate its logs properly.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...