Is this possible? I can't find any information online on this. I want to avoid indexing the files on-by-one, as there is too many and I would rather do them all in bulk.
Thanks.
Maybe the whitelist and/or blacklist keys in the monitoring stanza are what you're looking for? See the following
http://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata