Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Why are Spool Mail contents only shown partially in Splunk?

$
0
0
We have set up a Splunk monitor for getting contents of `/var/spool/mail/root` to Splunk. We are running a Splunk 6.2.8 Universal Forwarder on all the Linux hosts and the Splunk Enterprise version on the indexer is 6.2.1 splunk add monitor /var/spool/mail Though we are seeing the contents of root's mail on Splunk, they are partial as shown in the attachment. How do we make sure we list the full contents of root's mail rather than the first few lines. ![alt text][1] [1]: /storage/temp/122225-splunk-image.png

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>