I have some files that I need to index daily even though they may not change in content for several days (for example over weekends). The files are generated daily so they have a new creation and modification time. How can I force splunk to automatically index the file daily or use something like creation or modification time?
Hi duffeysplunk,
you have to insert in your inputs.conf the option crcSalt = <SOURCE>
and in your props.conf CHECK_METHOD = modtime
.
See
http://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Inputsconf
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
Bye.
Giuseppe
Hello,
Won't CHECK_METHOD=modtime lead to duplicate entries in splunk indexer as same data might get indexed again & again daily?
Hi duffeysplunk,
you have to insert in your inputs.conf the option crcSalt = <SOURCE>
and in your props.conf CHECK_METHOD = modtime
.
See
http://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Inputsconf
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
Bye.
Giuseppe
Thanks, that helped. I think I was mostly confused about where I put the CHECK_METHOD.