I am loading data to Splunk by monitoring a directory.
I would like to run a summary indexing search immediately after a new file is added only on that file.
Can anyone help me in doing this?
Summary indexing is based on a scheduled search. The search runs at regular intervals - regardless of whether there is any new data is added to a directory.
You could certainly schedule a populating search that examined only data where the source path matched the directory.
For more info on summary indexing, look here.
Summary indexing is based on a scheduled search. The search runs at regular intervals - regardless of whether there is any new data is added to a directory.
You could certainly schedule a populating search that examined only data where the source path matched the directory.
For more info on summary indexing, look here.