Getting Data In

Will Splunk re-index if inputs.conf changes and a file is rotated?

Branden
Builder

I have a large number of Universal Forwarders that forward Apache access logs. On my systems, the apache access logs are named -access.log and/or -ssl-access.log. On a regular basis, those files are rotated to -access.log.1 and/or -ssl-access.log.1. The .1 becomes a .2 after the next rotation, etc...

To simplify our environment a bit, I want to change our apache app to index "-access.log" or maybe even "*access". If I do the latter ("access") and restart the forwarder, will Splunk re-index all of the access log files? I do not want it to.

Thanks!

0 Karma

kristian_kolb
Ultra Champion

The fishbucket will keep track of what files have been indexed, and I don't think that it will care too much regarding the exact [monitor] stanza wording. Determining if a file has been read or not is more of an issue about checksums of the actual file(s) being monitored.

http://wiki.splunk.com/Community:HowSplunkReadsInputFiles
http://blogs.splunk.com/2008/08/14/what-is-this-fishbucket-thing/

One thing, though. If you create a common [monitor] for <hostname>-access.log and <hostname>-ssl-access.log, they would have to share the same sourcetype, which can be fine, if the contents (read: columns) of the file are the same. Have a read here as well;

http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Whysourcetypesmatter

/Kristian

Branden
Builder

Kristian,

Thank you for the helpful reply. Yes, I understand they would be sharing a common sourcetype, and I am fine with that. I was more concerned with duplicate entries, which from you describe shouldn't be an issue.
Thanks again!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...