we are running on Distributed Search Environment, we have two Heavy Forwarders. i'm actually unable to search estreamer logs so i have noticed this in splunkd.log
"Insufficient permissions to read file='/opt/syslogs/generic/mxwmexc02r/784861.log' (hint: No such file or directory , UID: 0, GID: 0). "
and one more warning message i have encountered "TailReader - File descriptor cache is full (100), trimming... " . Not sure why is this happening in only one forwarder and this is not happening in other?
↧