Mar 24, 2022, 9:00 – 10:00 PM (UTC)
Organizations may implement the rolling of log files on a periodic basis in Splunk. This could be daily, weekly or any frequency.
Organizations may implement the rolling of log files on a periodic basis. This could be daily, weekly or any frequency. One scenario that can happen is where Splunk does not realize that the rolled log file has new data and does not ingest as desired. It could be a file with the same name or even a separate file. This demo session is a walkthrough of how to troubleshoot ingestion issues and how to calculate and apply the necessary configuration settings to get Splunk rocking and [log] rolling again.
BitsIO
Sr Principal Consultant
bitsIO Inc.
VP at bitsIO Inc, Community Servant, SplunkTrust MVP and Positive Enabler
bitsIO
Co-Leader
Contact Us