Getting Data In

Forwarder is not forwarding all the files in directory.

kmisaal
New Member

I have configured a forwarder on Linux and receiver on different Linux box.

After restarting the forwarder I can see only the latest file got forwarded and on receiver only one file is indexed.

However I can see on forwarder there are multiple files got indexed. The data input for forwarder is "monitor file and directory" with the path of logs directory.

This logs directory has multiple log files.

Please let me know why forwarder is not forwarding all the files.

Tags (1)
0 Karma

LCM
Contributor

Hard to guess what the problem could be since a part got forwarded though!

Can you investigate following:

  • in the directory you're monitoring: create a new "dummy" file wich consist eg. "Hello World" (does that work - is it being indexed - can you see it on the receiver box)
  • modify one of the existing file with a new entry
  • check splunkd.log
  • netstat -a (although that should work 😉 )
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...