Monitoring Splunk

monitoring log truncated

rjfv8205
Path Finder

We have a service where logs are truncated. Example, we have hola.log that fridays copy all content to new file hola20190306.log and hola.log is empty.

My question, if universal forwarder monitoring hola.log, send info from begin or from position of the last event before truncated? Lost some events?

Sorry my english is not very good

Thank you in advance

Tags (1)
0 Karma

jnahuelperez35
Path Finder

It always send information from the last line that was generated.
If universal forwarder is monitoring the file named "hola.log" will monitor every line that was generated, after being empty or at leats all the lines goes to new "hola.log"

EDiT: you will never lost logs. i leave you this link that can help you to understand best practices about log rotation https://answers.splunk.com/answers/577144/about-log-rotation-best-practices.html

Let me know if i answer your question.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...