I have a minor issue whereby my Linux UF (an NFS server) is generating TailReader warnings in splunkd.log due to insufficient file permissions. It seems that the file permissions across the NFS mount are not being set quickly enough after creation for the Splunk user to read them on first pass. (the files are subsequently ingested) Example log messages:
The files are created on the NFS client, the UIDs are not matched between server and client, and perms are set 644. Whenever I look at the files on the Forwarder, some time after file creation, the files are all readable.
What I think is needed is a short (possibly a second or two) delay between Splunk detecting the presence of the file, and trying to read it. Is such functionality available ? I've searched the documentation and Answers here, but not found anything appropriate.
... View more