Originally posted by **extremepaperclip** October 22, 2023
Has anyone else experienced this?
Splunk is not ingesting the opencanary.log. I set up the monitor via inputs.conf (and I can successfully ingest if I run "tail -n 1 opencanary.log > test.log" Splunk ingests the test.log just fine). I have a support ticket open with Splunk Support, and so far they cannot figure this out as well.
If anyone has experienced this and solved the issue - please let me know what the fix was.
Thanks!! I love this project!
ExtremePaperClip
Discussed in https://github.com/thinkst/opencanary/discussions/317