Getting Data In

Forwarder is not forwarding all the files in directory.

kmisaal
New Member

I have configured a forwarder on Linux and receiver on different Linux box.

After restarting the forwarder I can see only the latest file got forwarded and on receiver only one file is indexed.

However I can see on forwarder there are multiple files got indexed. The data input for forwarder is "monitor file and directory" with the path of logs directory.

This logs directory has multiple log files.

Please let me know why forwarder is not forwarding all the files.

Tags (1)
0 Karma

LCM
Contributor

Hard to guess what the problem could be since a part got forwarded though!

Can you investigate following:

  • in the directory you're monitoring: create a new "dummy" file wich consist eg. "Hello World" (does that work - is it being indexed - can you see it on the receiver box)
  • modify one of the existing file with a new entry
  • check splunkd.log
  • netstat -a (although that should work 😉 )
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...