On an end node, how do I rotate introspection.log?
I see splunk can do it for its own logs like stdout and stderr via https://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Serverconf#Log_rotation_of_splunkd_stderr.l...
Is there a way to do the same for introspection logs too?
These logs are small and only hang around for 30 days. What possible reason could there be to much with these logs? This is internal to Splunk and I wouldn't mess with them, other than the clearly documented retention settings.
Hi,
This might help :
http://docs.splunk.com/Documentation/Splunk/7.1.3/Troubleshooting/Abouttheplatforminstrumentationfra...
You can try changing log.cfg for maxfilesize. Refer this link:
http://docs.splunk.com/Documentation/Splunk/7.1.3/Troubleshooting/Enabledebuglogging