We have a service where logs are truncated. Example, we have hola.log that fridays copy all content to new file hola20190306.log and hola.log is empty.
My question, if universal forwarder monitoring hola.log, send info from begin or from position of the last event before truncated? Lost some events?
Sorry my english is not very good
Thank you in advance
It always send information from the last line that was generated.
If universal forwarder is monitoring the file named "hola.log" will monitor every line that was generated, after being empty or at leats all the lines goes to new "hola.log"
EDiT: you will never lost logs. i leave you this link that can help you to understand best practices about log rotation https://answers.splunk.com/answers/577144/about-log-rotation-best-practices.html
Let me know if i answer your question.