Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why does data stop getting indexed for a monitored file when Splunk is restarted, and how do I fix this?

$
0
0
I am attempting to monitor a file that is fairly large and on a UNC file share. It appears that the file only indexes up to the point at which I reboot the Splunk indexer that is monitoring the file. I am not using a universal forwarder. I configured the file input directly from a Splunk indexer/search head. How would I make Splunk continue to monitor the file and add the data from after the Splunk reboot? The file also grows extremely large. Growing to over 200 meg. The source is a NetApp CIFS XML formatted log file. Thanks in advance,

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>