Hi,
Splunk can monitor a file like a tail -f command.
I would like to know how actually Splunk sees the file change,
how often Splunk see if the file has changed,
does Splunk actually o...
...nd found to be OK.
The related errors in the splunkd.log file are;
06-14-2014 08:00:08.608 -0600 ERROR TailingProcessor - Ignoring path due to: failed to open for checksum: '/var/tmp/xxx/xxx.log...
Hello
This is my DB tail config which I am trying to get the data from. But I get few errors in the dbx log. I guess I am making a mistake in placing the rising_column value. Any help would be g...
I am monitoring a directory with 101 csv file with the same format but I am having only 49 of them indexed. When I start up the splunk I get warn message from TailReader - Could not send data t...
...NFO WatchedFile [3338437 tailreader0] - Will use tracking rule=modtime for file='/path/.conf
INFO TailingProcessor [3338433 MainTailingThread] - Adding watch on path: /path
Please help me understand w...
I'm connecting to an Oracle database using a tail input. I've gotten it all working, however, splunk shows that the last update is yesterday afternoon when I initially set it up. I know there are n...
In this answer I can see there is ways to get the status of the tailing processor on a box. Only problem is it looks like it does not correctly report the status of .gz files.
What we are s...
I've been testing Splunk for several months now, and am consistently having problems with duplicate events appearing in the index. This sort of inconsistency is a show-stopper, so I decided to write...
I've got a local directory configured in my inputs.conf as so:
[monitor:///Volumes/A/b/c/dir]
disabled = false
followTail = 0
host = fubar
And this seemed to be working fine, but for No R...
...onitor another quite quickly growing file on this UF. And it's giving me headache. Some time after the UF starts, if restarted mid-day, I get TailReader - Enqueuing a very large file=\\<redacted&g...