Hi,
In our environment we have configured the Splunk Light Forwarder to monitor a log file and forward raw data form this file via TCP on a port of some other machine. We have built a custom server to listen on this port on that machine and consume raw events sent by Splunk Forwarder. This set up is working fine without any issues.
However, if our server goes down for any reason, we are seeing data loss and Light Forwarder doesn't forward all events after our server went down. We see that Light Forwarder does forward some data after it recognizes that server went down but NOT all of it.
I was wondering if there is a way to force the Light Forwarder to start sending events from certain point of time in a file. From the documentation it seems like Light Forwarder keeps track of the position in a file. Is there a way to manipulate this to start from different position.
Thanks,
Deepak Deshpande.
... View more