Trying to monitor a file that ends with .splunk but for some reason splunk will not index it. Only when I change the extension to .txt, it ingests. Any reasons why this is happening?
Thanks
@btawiah
This is the reason:
Files with a .splunk filename extension are also not monitored, because files with that extension contain Splunk metadata. If you need to index files with a .splunk extension, use the add oneshot CLI command.
You can read more here:
https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Monitorfilesanddirectories
@btawiah
This is the reason:
Files with a .splunk filename extension are also not monitored, because files with that extension contain Splunk metadata. If you need to index files with a .splunk extension, use the add oneshot CLI command.
You can read more here:
https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Monitorfilesanddirectories