...ia HTTP (htaccess protected) and FTP. Due to howthelogfiles are handled, their file names include the date.
Due to these servers belonging to ISPs, I cannot install the normal Splunk f...
...xplorer, renamed folder form "a4" to "b4" .
And repeated Step1 and pointed to D:\b4
However, after running search on the new data input directory, get no results. Checked C:\Program Files\Splunk\e...
In system/default/inputs.conf, I see a stanza like this ...
[monitor://$SPLUNK_HOME/var/log/splunk]
I don't see a file mask at the end of the path, so I assume that it is just going to i...
We have an issue where for some reason, Splunk stops reading a logfile in a particular Data Input folder. Thelog is set to roll hourly.
If we disable the Data Input, and then Re-Enable it, it s...
I have a mixed *nix and Windows environment and I'm currently collecting the Windows data with theSplunk Add-on for Microsoft Windows as event data. I want to start using theSplunk App for I...
Hi,
I noticed that, right after a logrotation, the data is not being indexed anymore.
Data is still going through /var/log/myapp.log and /var/log/messages (rsyslog UDP), so it all arrives on the...
...erver.
TheSplunk server has been filled to capacity and the partition where we store its logs is at 100%. So it seems like Like Rotation was never setup.
I read the info at this link below, b...
I have a source as ///application.log in my inputs.conf.On the servers the application.log will be rolled when it fill up with 10Mb by creating thefile name as application.12-13-2014.log and new file...
TheSplunk indexer and forwarders in my environment are configured to run as the "splunk" user for security reasons. Of course, this means that Splunk can no longer read root owned logfiles. The f...