<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic logfile folder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102981#M21622</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am having a logfile folder in which every day log file got created with the date name i want to index only latest 2 day's log file into splunk. what will be the configuration i have to make in my splunk universal forwarder (inputs.conf).&lt;/P&gt;

&lt;P&gt;Please suggest.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2012 07:16:26 GMT</pubDate>
    <dc:creator>vaibhavbeohar</dc:creator>
    <dc:date>2012-07-19T07:16:26Z</dc:date>
    <item>
      <title>logfile folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102981#M21622</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am having a logfile folder in which every day log file got created with the date name i want to index only latest 2 day's log file into splunk. what will be the configuration i have to make in my splunk universal forwarder (inputs.conf).&lt;/P&gt;

&lt;P&gt;Please suggest.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2012 07:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102981#M21622</guid>
      <dc:creator>vaibhavbeohar</dc:creator>
      <dc:date>2012-07-19T07:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: logfile folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102982#M21623</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;Any Suggestion ???&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2012 12:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102982#M21623</guid>
      <dc:creator>vaibhavbeohar</dc:creator>
      <dc:date>2012-07-25T12:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: logfile folder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102983#M21624</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In the inputs.conf use this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ignoreOlderThan = &amp;lt;time window&amp;gt;
* Causes the monitored input to stop checking files for updates if their modtime has passed this threshold.
  This improves the speed of file tracking operations when monitoring directory hierarchies with large numbers
  of historical files (for example, when active log files are colocated with old files that are no longer
  being written to).
  * As a result, do not select a cutoff that could ever occur for a file
    you wish to index.  Take downtime into account!  
    Suggested value: 14d , which means 2 weeks
* A file whose modtime falls outside this time window when seen for the first time will not be indexed at all.
* Value must be: &amp;lt;number&amp;gt;&amp;lt;unit&amp;gt; (e.g., 7d is one week).  Valid units are d (days), m (minutes), and s (seconds).
* Default: disabled.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 25 Jul 2012 13:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/logfile-folder/m-p/102983#M21624</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2012-07-25T13:18:57Z</dc:date>
    </item>
  </channel>
</rss>

