Monitoring Splunk

monitoring log truncated

rjfv8205
Path Finder

We have a service where logs are truncated. Example, we have hola.log that fridays copy all content to new file hola20190306.log and hola.log is empty.

My question, if universal forwarder monitoring hola.log, send info from begin or from position of the last event before truncated? Lost some events?

Sorry my english is not very good

Thank you in advance

Tags (1)
0 Karma

jnahuelperez35
Path Finder

It always send information from the last line that was generated.
If universal forwarder is monitoring the file named "hola.log" will monitor every line that was generated, after being empty or at leats all the lines goes to new "hola.log"

EDiT: you will never lost logs. i leave you this link that can help you to understand best practices about log rotation https://answers.splunk.com/answers/577144/about-log-rotation-best-practices.html

Let me know if i answer your question.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...