Alerting

How to index a complete file every 24 hours?

msilvareal
New Member

Dear all,

Is it possible to index a complete file every 24 hours, even if it has no change?

Thanks in advance for the help.

0 Karma

evania
Splunk Employee
Splunk Employee

Hi @msilvareal ,

Did you have a chance to check out any answers? If any work, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.

Thanks for posting!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk tries to avoid re-indexing the same unchanged file. This saves your license costs. If you really want to re-index the same data, one slightly ugly approach is to schedule a scripted input to run every 24 hours. The script can be a few lines of python code that read the file and write it to stdout, which Splunk will index.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...