Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Can symlink cause Splunk to index files twice?

$
0
0

Due to some inconsistencies in how some of our servers use Symbolic Links (symlinks), we need to understand how Splunk would handle the following situation...

/usr2/wlp_logs is a symlink pointing to /hosting/logs.

If we have the following 2 monitor stanzas in inputs.conf...

[monitor:///usr2/wlp_logs/blah/myapp.log]

[monitor:///hosting/logs/blah/myapp.log]

...would Splunk recognize that these are 2 references to the same file, and index it only once? Or, would myapp.log get indexed twice?

Thx for any clarification / enlightenment.

mfeeny1


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>