Hi all, i have a question
Index= app-data "cgth14678ghj" host= http:jbossserver source=application_data_http:jbossserver-20210102-10.log
When i search with this query in will get events in Splunk
But when i see on the host side there are no events with this term cgth14678ghj on the source file
How come there are displaying on splunk without being in server
From were splunk is taking this data which is not there in server.
Can any help me on this???
have you looked what are log processors which are configured into jboss server? There could be several different processors some write file and some could write directly to tcp socket.