Hi *,
I'm in development environment and I'd like to not receive all the old data from the agent.
I have one server and some agents, and I delete indexes for cleaning reasons from Splunk server, but when I restart the splunk service, all the old data comes through.
How can I tell the agents (or the server) to not send me the events before 1 day?
Or before 3 hours ... or anything custom.
Thanks!
With regular file-monitor inputs you can use the ignoreOlderThan
directive. For instance
[monitor:///path/to/the/input]
ignoreOlderThan = 1d
http://docs.splunk.com/Documentation/Splunk/5.0/Admin/Inputsconf
With regular file-monitor inputs you can use the ignoreOlderThan
directive. For instance
[monitor:///path/to/the/input]
ignoreOlderThan = 1d
http://docs.splunk.com/Documentation/Splunk/5.0/Admin/Inputsconf