We have an app input config monitor containing wildcards with whitelist configured to pick up only .log and .out. There are about 120 log files matching the whitelist regex. All the logfiles are ingesting fine except for 1 specific logfile that seems unable to continue the ingestion after log rotation. crcSalt and initCrcLength already defined as below - initCrcLength = 1048576 crcSalt = <SOURCE> On splunkd.log, the below event can be found - 05-15-2024 00:32:57.332 -0400 INFO WatchedFile [16425 tailreader0] - Logfile truncated while open, original pathname file='/xxx/catalina-.out', will begin reading from start. Is 120 logs on 1 input too many for Splunk to handle? How can we resolve this issue?
... View more