Getting Data In

ingesting huge file continuously

cleelakrishna
Loves-to-Learn

we have seen as issue where Splunk UF stops reading a specific file once file gets more than 20MB , and going to batch process ( which is waiting till file to complete)  ,  My file gets Realtime data and reaches >1GB in 3 hours. which splunk cannot read that huge file. Please provide the config settings that i need to change for Splunk to read continuously .

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @cleelakrishna 

Can you share the monitor stanza configured in inputs.conf and outputs conf on UF?

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...