Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk is ingesting archived data from our syslog servers

$
0
0
we have a syslog server with UF installed on it and my inputs.conf states /opt/splunk/syslogs/cisco/acs/*/* and my logrotate.d has syslog-ng that states /opt/splunk/syslogs/*/*/*/syslog. Due to the logrotate daily cron job there are directroies created with dateext and .gz in the same directory and Splunk forwarder is reading them and resending it to indexers how do i stop this?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>