I have CSV files that are point-in-time snapshots of a configuration. If any part of the CSV changes, I'd like the contents of the entire CSV file to be re-indexed and not just the lines that changed. I hope to reference each "version" of the CSV's contents in Splunk by the index time.
I've tried playing with the different options for the CHECK_METHOD option for props.conf, but it continues to only index the lines that have changed rather than the entire file.
inputs.conf:
[monitor://C:\baselines\BaselinePorts.csv]
index = tracking
sourcetype = baselines
props.conf
[baselines]
FIELD_DELIMITER=,
HEADER_FIELD_DELIMITER=,
CHECK_METHOD=endpoint_md5