I have two different file names in the same directory on a forwarder. The problem is, the data for both files are the same, so how do I allow all the events to be indexed on my receiver side?
Monitor individual files instead of the whole directory.
How do i monitor individual files ? Is there an example ?
Hi @englishjohn
If the answer by @richgalloway solved your issue, please don't forget to resolve the post by clicking "Accept" directly below his answer. If you're still having issues, please comment with more details.
Thanks!
In your [monitor://]
stanza name, put a path to an individual file instead of to a directory. See http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Inputsconf for more.