<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log ingestion with line level delete in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-ingestion-with-line-level-delete/m-p/689646#M114781</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/120193"&gt;@bworrellZP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you could use (only in lab) the syslog network input that doesn't write on disk.&lt;/P&gt;&lt;P&gt;Otherwise, use rsyslog, writing syslog on disk and then read these logs using the batch command, instead monitor, in the inputs.conf.&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this way logs are deleted soon after ingestion.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 06:15:13 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-06-05T06:15:13Z</dc:date>
    <item>
      <title>Log ingestion with line level delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-ingestion-with-line-level-delete/m-p/689620#M114777</link>
      <description>&lt;P&gt;This evening decided to setup a test Splunk box in my lab to goof around with.&amp;nbsp; Been a while since I have done this part of the process. (Work cluster is up and going and has been for years now).&amp;nbsp; As I was looking at my local test box, I noticed the hard drive was not likely the best size to use.&lt;BR /&gt;&lt;BR /&gt;So since I have a syslog server running on this as well, and I am pulling those files into Splunk (Splunk will not always be running, hence not sending data direct to Splunk), wanted to try doing a line level destructive read.&lt;BR /&gt;&lt;BR /&gt;I did see where others were using a monitor and deleting a file on ingestion, but did not see if line level was being done.&lt;BR /&gt;&lt;BR /&gt;So, question is, has anyone done that, and if so, do you have some hints or pointers?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 00:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-ingestion-with-line-level-delete/m-p/689620#M114777</guid>
      <dc:creator>bworrellZP</dc:creator>
      <dc:date>2024-06-05T00:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingestion with line level delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-ingestion-with-line-level-delete/m-p/689646#M114781</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/120193"&gt;@bworrellZP&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you could use (only in lab) the syslog network input that doesn't write on disk.&lt;/P&gt;&lt;P&gt;Otherwise, use rsyslog, writing syslog on disk and then read these logs using the batch command, instead monitor, in the inputs.conf.&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Inputsconf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this way logs are deleted soon after ingestion.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 06:15:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-ingestion-with-line-level-delete/m-p/689646#M114781</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-05T06:15:13Z</dc:date>
    </item>
  </channel>
</rss>

