Splunk Search

Frequency lea updates pointer file

sdwilkerson
Contributor

Hello,

Does anyone know the frequency that the lea-loggrabber-splunk app's lea_loggrabber process should write to its record-number cache lea_log_rec_num.cache?

It seems that when Splunk is restarted or if lea_loggrabber is HUPd that this pointer file is not written to so next time the process starts, it gets lots of old data.

Also, a side note, is that because this pointer file is written to locally, you CANNOT use Splunk's Deployment Server to push this app since it will over write this record at each deployment/restart.

Thanks,

Sean

0 Karma
1 Solution

sdwilkerson
Contributor

Answering my own post here.
From what I can tell, the lea_log_rec_num.cache file only gets updated upon completion of the script run, meaning, the lea-connector has reached the end of the Checkpoint log file.

Therefore, in a high-volume environment, it could take a long time for this script to finish its initial run.

Sean

View solution in original post

sdwilkerson
Contributor

Answering my own post here.
From what I can tell, the lea_log_rec_num.cache file only gets updated upon completion of the script run, meaning, the lea-connector has reached the end of the Checkpoint log file.

Therefore, in a high-volume environment, it could take a long time for this script to finish its initial run.

Sean

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...