Getting Data In

Why is my application log not getting created after we installed a universal forwarder?

Abilan1
Path Finder

Hi ,

We have installed one third party tool in our server and we wanted to forward those tool logs to a Splunk indexer, so we have configured universal forwarder in that machine and it is forwarding the logs to indexer without any issues. We have configured in that tool so that after the log size grown it to 10 MB, it renames this log file and creates a new log file with that same name. But what we noticed is after we installed universal forwarder, once the log size is grown it to 10 MB, my tool is renaming the log file and it is not creating the new log file. Not sure why it is behaving like this? We never faced this issue before, please help.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Try logrotate, or talk to the vendor of that third-party tool failing to rotate its logs properly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...