<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to invoke Splunk daemon to parse newly added file right away in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-invoke-Splunk-daemon-to-parse-newly-added-file-right-away/m-p/55482#M10830</link>
    <description>&lt;P&gt;Since I usually turned of splunkd service on my local machine and only turn it back on when I need to do some log search. &lt;/P&gt;

&lt;P&gt;Chances that when I turn the daemon back on, I will have some more files that needs to be indexed right away for search. Is there any way can make Splunk daemon do this? There may be 2 cases:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;index a file in an already under tracked folder.&lt;/LI&gt;
&lt;LI&gt;index a random file that's not under tracking folder.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2010 05:22:57 GMT</pubDate>
    <dc:creator>Stan</dc:creator>
    <dc:date>2010-09-22T05:22:57Z</dc:date>
    <item>
      <title>How to invoke Splunk daemon to parse newly added file right away</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-invoke-Splunk-daemon-to-parse-newly-added-file-right-away/m-p/55482#M10830</link>
      <description>&lt;P&gt;Since I usually turned of splunkd service on my local machine and only turn it back on when I need to do some log search. &lt;/P&gt;

&lt;P&gt;Chances that when I turn the daemon back on, I will have some more files that needs to be indexed right away for search. Is there any way can make Splunk daemon do this? There may be 2 cases:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;index a file in an already under tracked folder.&lt;/LI&gt;
&lt;LI&gt;index a random file that's not under tracking folder.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2010 05:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-invoke-Splunk-daemon-to-parse-newly-added-file-right-away/m-p/55482#M10830</guid>
      <dc:creator>Stan</dc:creator>
      <dc:date>2010-09-22T05:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to invoke Splunk daemon to parse newly added file right away</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-invoke-Splunk-daemon-to-parse-newly-added-file-right-away/m-p/55483#M10831</link>
      <description>&lt;P&gt;The file that is already under a tracked folder should be picked up automatically by splunk as soon as it gets turned on.&lt;BR /&gt;
To monitor the new file all you have to do is login to splunk, go to manager, then data inputs and then files and directories. There you can tell splunk to monitor the new file and the parsing should start immediately. Follow these breadcrumbs: 
Manager » Data inputs » Files &amp;amp; Directories » Add New &lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2010 05:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-invoke-Splunk-daemon-to-parse-newly-added-file-right-away/m-p/55483#M10831</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-09-22T05:57:08Z</dc:date>
    </item>
  </channel>
</rss>

