Looking at LogFileEventPoller, I would say no. If the file is renamed, it will miss the last part.
You can probably get more reliable results using the Syslog port monitoring.
There's been talk of using a different log monitoring system as well as moving events to Elasticsearch. Not sure if any progress is happening in the short term.
So it is possible to miss the last part of the log file if it rolls in between the polls ?
Does RHQ currently support ELK or are there plans to support it?