Splunk Search

rotating sylog file

huaraz
Explorer

Hi,

How is splunk dealing with logfiles which rotate like syslog ? Will splunk loose data during the rotation ?

To add some details. I assume Splunk checks on a regular basis if the logfile exists and reads new unindexed data from the logfile. If the logfile is rotated between the Splunk checks data get lost or ?

Markus

Tags (2)
0 Karma

Ayn
Legend

No, it will not. See gkanapathy's answer to this (identical) question: http://splunk-base.splunk.com/answers/10309/log-file-rotation

huaraz
Explorer

It answers one part of my question

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...