Getting Data In

ingesting huge file continuously

cleelakrishna
Loves-to-Learn

we have seen as issue where Splunk UF stops reading a specific file once file gets more than 20MB , and going to batch process ( which is waiting till file to complete)  ,  My file gets Realtime data and reaches >1GB in 3 hours. which splunk cannot read that huge file. Please provide the config settings that i need to change for Splunk to read continuously .

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @cleelakrishna 

Can you share the monitor stanza configured in inputs.conf and outputs conf on UF?

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...