Getting Data In

How to re index the same file within a specified time?

msilvareal
New Member

Good afternoon,

It is possible to index the same complete file within a certain period of time.

Example: I have a configuration file with approximately 2000 lines and 61kb, I needed to index this file once every 6 hours.

Would anyone have any ideas? I tried to make some settings in the file input.conf and props.conf, but all without success.

Thanks in advance for your support.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

One slightly ugly approach is to schedule a scripted input to run every 6 hours. The script can be a few lines of python code that read the file and write it to stdout, which Splunk will index.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...