splunk / splunk/addonfactory-solutions-library-python
Log rotation is not functioning properly for multi-instance Splunk TAs.
@artemrys ci sta già lavorando.
Dal 3/1/2025.
- Lingua principale
- Python
- Stelle
- 18
- Fork
- 10
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
Description:
Log rotation is not functioning properly for multi-instance Splunk TAs.(This may be considered an ENHANCEMENT) and gets rotated multiple times and out-of-time by different inputs. I think this issue is happening since each input is a separate process in multi-instance mode while in single-instance the log instance is singleton between all threads (inputs). We've received some customer issues regarding the same.
Steps to reproduce:
- Create multiple TA inputs that support multi-instance configurations (e.g., TA with multi-instance options like Snow, Remedy, Box). Let the log file threshold to reach (25 MB by default).
- Check the log files:
- If more than five inputs are enabled, five backup log files are created at the same time.
- If fewer than five inputs are enabled, the number of backup log files created corresponds to the number of enabled inputs.
Expectation:
Only one backup log file (.log.1) should be created when the log file reaches the maxBytes limit.
Actual:
When the .log file first time reaches the maxBytes limit, each process/input tries to rotate the logs files individually (.log.1, .log.2, .log.3, .log.4, .log.5), instead of rotating just one log file (.log.1). If more than five inputs are enabled, five backup log files are created at the same time; if fewer than five inputs are enabled, the number of backup log files created corresponds to the number of enabled inputs.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Valutazione
Questa issue non è ancora stata valutata.