All,
I have a CSV being laid to a file system by a database.
A basic monitor stanza brought the file in perfect with sourctype=csv. However, when a new file is loaded with the same name, Splunk does not bring in the file with the new contents. Any idea on how to get Splunk to reread the file?
Not sure why but a forwarder restart solved this. Just worked.