Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

File not being read by Splunk in a directory while others are

$
0
0
Hi, I have a directory which is defined in inputs.conf on a host (which has UF running), directory is: /var/middleware/inventory/var As per the logs (splunkd.log), the directory is now monitored: 10-04-2017 11:50:50.105 +0200 INFO TailingProcessor - Adding watch on path: /var/middleware/inventory/var. In this directory there are nine different files. But only eight of them are read. They all have the same permissions and the content format is also the same. Does anyone know why the last file is not being read by Splunk? There is no log about it. Thanks for your help.

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>