Using patterns to select rolled logs

You may notice that the previous stanza ended in *. This is important because it gives Splunk a chance to find events that were written to a log that has recently rolled. If we simply watch /logs/interesting.log, it is likely that events will be missed at the end of the log when it rolls, particularly on a busy server.

There are specific cases where Splunk can get confused, but in the vast majority of cases, the default mechanisms do exactly what you would hope for. See the When to use crcSalt section further on for a discussion about special cases.

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.