Getting Data In

automatic update row in a index file

tissparkle
Explorer

Hi, I put a file in a specific directory to be indexed.
This file is update in a automatic way in a directory.

My issue is:
The index file makes a sum of the old file and the new file events and this is not correct for my use. for example: 1° file is 200 events - after that the second time file is 200+10 new events.
I would like to have a result of the index like 210 events not 410 events. I would like to understand if there is a different way to delete the old index and make everything automatic. thanks a lots

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk always appends new data to the existing old data. Your case sounds like a lookup rather than indexed data, take a look at http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions for more info.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...