I have set up a Data input in Splunk which allows me to search a series of CSV files conatined within this folder.
Each file is identical in structures and each file represents a particular months worth of data (ie Jan-2014.csv, Feb-2014 etc).
the Data for these files originates from a SQL server Databae and are generated as part of a nightly extract where by the data is returned from the Start of the Month to the current date. Results are then saved in a file that looks something like MyFilename_[CurrentMonth]_[CurrentYear].CSV.
I initially created a series of monthly files that went allthe way back to Jan 2013 and put them into the Input folder. Once this was doen I could search this data effectively...
However....
Subsequent loads where the latest months data is being recreated with updated data are not appearing in my Splunk Searches!!!
I've taken a look at the Latest Months Data File and (using Excel) observed that there is recent data in it...but for some reason Splunk is not picking up any new data since the time of that inital load...
Please help!!!
... View more