List of questions
Related questions
Question 121 - SPLK-2002 discussion
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
A.
An admin ran splunk clean eventdata -index <indexname> on the indexer.
B.
An admin has removed the Splunk fishbucket on the forwarder.
C.
The last 256 bytes of the monitored file are not changing.
D.
The first 256 bytes of the monitored file are not changing.
Your answer:
0 comments
Sorted by
Leave a comment first