Getting Data In

monitor a file using tail initially blank



I have a file being monitored like this:
where xxxxxxxxxx is the filename and index name

followTail = 1

Initially the file does not exist, however, when it is created the first event is skipped, all following events are caught as normal.

Is this normal behaviour? and if so is there away to capture that first event?


Tags (2)
0 Karma


There is no need to use followTail, especially when the file does not yet exist.

Additionally, it is advised by Splunk that you NOT use followTail:

Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...