how to judge if a file was eaten by splunk, and then i can delete or move it immediately?
Use Batch stanza instead of monitor:
http://docs.splunk.com/Documentation/Splunk/6.0/admin/inputsconf
Regards
View solution in original post