Hi,
How is splunk dealing with logfiles which rotate like syslog ? Will splunk loose data during the rotation ?
To add some details. I assume Splunk checks on a regular basis if the logfile exists and reads new unindexed data from the logfile. If the logfile is rotated between the Splunk checks data get lost or ?
Markus
No, it will not. See gkanapathy's answer to this (identical) question: http://splunk-base.splunk.com/answers/10309/log-file-rotation
It answers one part of my question