facing this issue second time, and tried almost every possible way out in last 2 months, so here is the csv file we're which is getting referesh in every 1 hour, ( it may or may not contain new events ) We observed after few hours file stop getting into splunk and after splunk restart again it start ingesting data. In the splunkd logs its says ignoring path, I have tried crcSalt, initCrcLenth but non worked in my case All i want splunk is to read new file always no matter is there is new events or not, just stay updated with file ( i cannot add counter in file )
... View more