Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

Why is Splunk still getting logs from an edited source path?

$
0
0
I recently edited the path of a source in inputs.conf in a heavy forwarder but I kept receiving events from both ( the new and the old source ). the old one : [monitor:///var/portal/tomcat/log/jms.log] disabled = false index = APP_Cle sourcetype = APP_jms I edited the file then it became : [monitor:///var/portal/local/log/jms.log] disabled = false index = APP_Cle sourcetype = APP_jms Is this normal ? What should I do to stop receiving events from the old source ?

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>