I have the following entry in my $SPLUNK_HOME/etc/system/local/inputs.conf file --
[monitor:///appl/sharp/logs/*.fip]
host = trpramprptapp1.vm.itg.corp.us.shldcorp.com
sourcetype = sharp_fip
index = sharp
ignoreOlderThan = 1d
the dahsboard that we have is still reindexing all the log files, even thoough we have specified to not index the data older than 1 day.