I have been battling this for weeks. With the help of this post, I finally discovered that the log files received from a vendor do not have a modification time and a simple "touch $FILE" on Linux enables a nice clean ingest and timestamp parsing. Woohoo! THANKS!
... View more
This is what I needed to do after rsyncing the entire /opt/splunk folder over to a new file system to move splunk off of the root file system. Thanks for the help!!
... View more