Hi, I'm new in Splunk and I'm looking for some help for the following use case:
at Splunk indexes all new files in a folder, each file represents an event, but the files that arrive are many.
I would like to index only the files that contain a data value to a tag (eg "
You may want to consider a scripted input to apply some additional logic to the collection.
http://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf