Getting Data In

Why is my application log not getting created after we installed a universal forwarder?

Abilan1
Path Finder

Hi ,

We have installed one third party tool in our server and we wanted to forward those tool logs to a Splunk indexer, so we have configured universal forwarder in that machine and it is forwarding the logs to indexer without any issues. We have configured in that tool so that after the log size grown it to 10 MB, it renames this log file and creates a new log file with that same name. But what we noticed is after we installed universal forwarder, once the log size is grown it to 10 MB, my tool is renaming the log file and it is not creating the new log file. Not sure why it is behaving like this? We never faced this issue before, please help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Try logrotate, or talk to the vendor of that third-party tool failing to rotate its logs properly.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...