After calling splunk/forwarder/bin/splunk add oneshot , is it ok to delete the file I just added, or does the file need to be kept on disk for the forwarder to give it to the splunk enterprise server receiver?
After calling splunk/forwarder/bin/splunk add oneshot , it is ok to delete the file. maybe, make sure the file got ingested(on splunk gui, you can run the search query for the file)
https://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI
Copy the file directly into Splunk. This uploads the file once, but Splunk Enterprise does not continue to monitor it.
You cannot use the oneshot command against a remote Splunk Enterprise instance. You also cannot use the command with either recursive folders or wildcards as a source. Specify the exact source path of the file you want to monitor.
I am not sure about oneshot, but you can try batch input for your requirement.