![]() ![]() The logs get rotated/saved as e.g:/opt/app/ws/server/ra_JVM00/log/server.log., i don't think splunk will read this as we did not give that in monitor stanza.Ĭan you please shed some light on this. opt/app/ws/server/pr_INS02/log/server.log opt/app/ws/server/pr_INS00/log/server.log When I remove the SSL requirement from the remote end, the data shows up as. After modifing the config and changing the remote end to use SSL, I get gibberish like this. configuration, Splunk Universal Forwarder. and add that line to at bottom of file or in local directory create a nf and put the info there and restart splunk service. organizing, apps used / Using apps to organize configuration. splunktcp:// ![]() Each stanza controls different search commands settings. why do you have the crcSalt View solution in original post. Version 9.1.0 OVERVIEW This file contains possible settings you can use to configure inputs, distributed inputs such as forwarders, and file system monitoring in nf. opt/app/ws/server/ra_JVM01/log/server.log nf The following are the spec and example files for nf. opt/app/ws/server/ra_JVM00/log/server.log The actual path of the monitor stanza would include. The input configuration specification file must be named, and must be located in SPLUNKHOME/etc/apps/ appname /README/. ![]() I have my nf in here i did tried with followTail and initCrcLength which doesn't work to get rid of the above messages. INFO WatchedFile - Logfile truncated while open, original pathname file=.''. scp the file to a different directory, then mv it to the batch directory. Write a script to remove the files from the directory after 24 hours or 7 days or whatever makes sense. INFO WatchedFile -File too small to check seekcrc, probably truncated. Use monitor:// instead of batch in your nf. I'm getting bunch of there messages on our UFs. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |