Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Monitored logs file (located in UNC path) has been re injected each time new line added.

$
0
0
Our Splunk monitoring and log file located on a network share. New line is always added into bottom of the file. Everytime when there is new line added into the log, the entire log file got injected again, my input.conf as below [monitor://\\nfs1\logs$\audit.xml] disabled = 1 index = sservice sourcetype = app Any suggestions on where am I doing it wrong? Should I use followTail setting? in Splunk documentation website it says "DO NOT leave followTail enabled in an ongoing fashion" so I didnt try it.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>