Splunk Search

forward not detect changes

indeed_2000
Motivator

Hi

I install forwarder on a server.

it work perfectly and forward anything on this path /data/app/log to splunk server, but after server disk space run out, I try to delete a file "server.log" on this path, then restart my app to create new server.log on that path. file create again successfully but after this action forwarder not detect changes. 

I try to restart forwarder but not affected!

any idea?

Thanks,

Labels (3)
Tags (2)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @indeed_2000 

Could be a possible fishbucket issue, you can check the current monitor status by issuing command under $SPLUNK_HOME/bin use the "./splunk list inputstatus" to get more detailed info on where Splunk is in reading the different files. If you do not find any clue here, you can remove fishbucket directorty/reset -

Clear fishbucket: Declaimer:  The data already indexed might re-index.

----

An upvote would be appreciated if it helps!

venkatasri
SplunkTrust
SplunkTrust

@indeed_2000 It would be great if the steps have provided the fix then accept the solution.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...