You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-F The -F option implies the -f option, but tail will also check to see if the file being
followed has been renamed or rotated. The file is closed and reopened when tail
detects that the filename being read from has a new inode number.
In my current environment I have splunk running container image 9.0.6 and have verified the tail command is running via ps aux | grep tail and logs are actively being written to splunkd_stderr.log. I've also confirmed logs stopped being written to stdout immediately after file rotation splunkd_stderr.log -> splunkd_stderr.log.1.
The text was updated successfully, but these errors were encountered:
zarend
pushed a commit
to zarend/docker-splunk
that referenced
this issue
Aug 26, 2024
Fix issue with logging of standard error messages where standard error
logs would be lost when logging large amount of data to stadard error.
Splunk logs to splunkd_stdout.log as the Unix standard error device.
This file is rotated. According to [What Splunk software logs about itself](https://docs.splunk.com/Documentation/Splunk/9.2.1/Troubleshooting/WhatSplunklogsaboutitself), "The historical rotation for most internal logs is 5 files of 25MB each".
docker-splunk container tails the output of splunkd_stdout.log to
standard output. The existing behavior is that the container receives
Splunk's standard error messages until splunkd_stdout.log is about 25MB.
When the log files passes 25MB, Splunk rotates the log file by rename
splunkd_stdout.log to something like splunkd_stoudt1.log and creating a
new splunkd_stdout.log.
By default, tail follows the file descriptor of argument file. I believe
that if the file is renamed, it continutes to track the file descriptor
of argument file, if that is available. This is not the behavior we want
for file rotation, since we always want to follow the information that
goes to splunkd_stdout.log and not splunkd_stdout1.log,
splunkd_stdout2.log, etc.
Fix standard error logs not surfacing by passing `-F` option to unix
tail command. This causes tail to keep retrying to open argument file
name if it becomes unavailable.
Change in behavior to print standard error logs to standard out for
entire lifetime of the program, instead of stopping after the first file
rotation.
Fixsplunk#626
The tail command used to emit
splunkd_stderr.log
(or a custom log file) to stdout does not handle the file being rotated/renamed. The current command uses-f
https://github.com/splunk/docker-splunk/blob/9.1.1/splunk/common-files/entrypoint.sh#L65 but likely should use-F
In my current environment I have splunk running container image 9.0.6 and have verified the tail command is running via
ps aux | grep tail
and logs are actively being written tosplunkd_stderr.log
. I've also confirmed logs stopped being written to stdout immediately after file rotationsplunkd_stderr.log -> splunkd_stderr.log.1
.The text was updated successfully, but these errors were encountered: