Hi ,
We have installed one third party tool in our server and we wanted to forward those tool logs to a Splunk indexer, so we have configured universal forwarder in that machine and it is forwarding the logs to indexer without any issues. We have configured in that tool so that after the log size grown it to 10 MB, it renames this log file and creates a new log file with that same name. But what we noticed is after we installed universal forwarder, once the log size is grown it to 10 MB, my tool is renaming the log file and it is not creating the new log file. Not sure why it is behaving like this? We never faced this issue before, please help.
Try logrotate, or talk to the vendor of that third-party tool failing to rotate its logs properly.