Getting Data In

scheduler.log is not rolling in Splunk enterprise

sivapuvvada
Path Finder

Hi Team ,

we are not seeing scheduler.log in splunk .

we have tried the below option but no luck

default-mode.conf file :
[pipeline:scheduler]
disabled = false

and also updated savedsearches.conf enableSched = 1

Tags (1)
0 Karma
1 Solution

sivapuvvada
Path Finder

Disable the Spluklightforwarder app under the etc/apps directory .

View solution in original post

0 Karma

sivapuvvada
Path Finder

Disable the Spluklightforwarder app under the etc/apps directory .

0 Karma

p_gurav
Champion

Did you checked at $SPLUNK_HOME/var/log/splunk?

0 Karma

sivapuvvada
Path Finder

yes i checked scheduler.log is not present and nothing is showing in splunkd.log for scheduler

0 Karma

adonio
Ultra Champion

can you elaborate?
where are you looking for the log? is it a distributed environment?

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...