Aha - Found it in apps/search:
-bash-3.2$ more inputs.conf
[monitor:///logs/remote/.../*.log]
disabled = false
index = issec
sourcetype = syslog
... View more
I'm getting the same problem. Splunk Universal Forwarder on Linux, accessing file data. When the forwarder stops working, we restart the forwarder and it ingests data again, but not for that entire gap that it was down.
... View more