I'm using the universal forwarder on Solaris.
I set up the following input:
[monitor:///var/log]
disabled = false
index = syslog
and then discovered the joy of /var/log/pool/poold, to which the system writes once every fifteen seconds. We don't really need or care about that log, so I added
blacklist = .*poold$
and restarted the forwarder. I can see from the output of "splunk list monitor" that the file is no longer supposedly being watched, but I'm still getting new events from it!
Someone else here mentioned that they used "splunk clean eventdata" to clear up this sort of problem, but that only works with the full Splunk install, not with the universal forwarder.
Any ideas?
... View more