<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best way to use a universal forwarder to monitor a file that overwrites itself at random periods throughout the day? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140644#M28820</link>
    <description>&lt;P&gt;Relevant Questions / Answers:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/61006/file-system-monitoring-of-text-files-that-are-overwritten.html"&gt;http://answers.splunk.com/answers/61006/file-system-monitoring-of-text-files-that-are-overwritten.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/6482/appending-vs-overwriting-tailed-log-files.html"&gt;http://answers.splunk.com/answers/6482/appending-vs-overwriting-tailed-log-files.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/218638/if-i-have-a-monitored-log-file-with-lines-that-are.html"&gt;http://answers.splunk.com/answers/218638/if-i-have-a-monitored-log-file-with-lines-that-are.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/2073/when-a-file-is-already-set-to-index-to-splunk-and-that-file-gets-overwritten-with-updates-meaning-instead-of-file-being-appended-does-splunk-smart-enough-to-not-to-reindex-already-indexed-data-and-only-index-whats-newly-aded.html"&gt;http://answers.splunk.com/answers/2073/when-a-file-is-already-set-to-index-to-splunk-and-that-file-gets-overwritten-with-updates-meaning-instead-of-file-being-appended-does-splunk-smart-enough-to-not-to-reindex-already-indexed-data-and-only-index-whats-newly-aded.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2015 23:05:01 GMT</pubDate>
    <dc:creator>aljohnson_splun</dc:creator>
    <dc:date>2015-07-28T23:05:01Z</dc:date>
    <item>
      <title>What is the best way to use a universal forwarder to monitor a file that overwrites itself at random periods throughout the day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140643#M28819</link>
      <description>&lt;P&gt;Hoping that someone has seen this before and might be able to help.&lt;/P&gt;

&lt;P&gt;I'm fairly new to SPLUNK and I am attempting to send to the indexer a monitored file. This log file overwrites itself throughout the day at random periods based upon the software that generates it. I need to be able to have the file read and the contents pushed to the indexer. I need to make sure that we do not get duplicate values nor miss data from within the file.&lt;/P&gt;

&lt;P&gt;We are utilizing SPLUNK 6.1 and the Windows Universal Forwarder to monitor the file. Any insight on the best practice for this scenario would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 21:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140643#M28819</guid>
      <dc:creator>rfoley</dc:creator>
      <dc:date>2015-07-28T21:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to use a universal forwarder to monitor a file that overwrites itself at random periods throughout the day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140644#M28820</link>
      <description>&lt;P&gt;Relevant Questions / Answers:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/61006/file-system-monitoring-of-text-files-that-are-overwritten.html"&gt;http://answers.splunk.com/answers/61006/file-system-monitoring-of-text-files-that-are-overwritten.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/6482/appending-vs-overwriting-tailed-log-files.html"&gt;http://answers.splunk.com/answers/6482/appending-vs-overwriting-tailed-log-files.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/218638/if-i-have-a-monitored-log-file-with-lines-that-are.html"&gt;http://answers.splunk.com/answers/218638/if-i-have-a-monitored-log-file-with-lines-that-are.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/2073/when-a-file-is-already-set-to-index-to-splunk-and-that-file-gets-overwritten-with-updates-meaning-instead-of-file-being-appended-does-splunk-smart-enough-to-not-to-reindex-already-indexed-data-and-only-index-whats-newly-aded.html"&gt;http://answers.splunk.com/answers/2073/when-a-file-is-already-set-to-index-to-splunk-and-that-file-gets-overwritten-with-updates-meaning-instead-of-file-being-appended-does-splunk-smart-enough-to-not-to-reindex-already-indexed-data-and-only-index-whats-newly-aded.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 23:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140644#M28820</guid>
      <dc:creator>aljohnson_splun</dc:creator>
      <dc:date>2015-07-28T23:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to use a universal forwarder to monitor a file that overwrites itself at random periods throughout the day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140645#M28821</link>
      <description>&lt;P&gt;A standard file &lt;CODE&gt;monitor&lt;/CODE&gt;-based &lt;CODE&gt;inputs.conf&lt;/CODE&gt; entry should work just fine.  It may give you some warm fuzzies to use a &lt;CODE&gt;batch&lt;/CODE&gt;-based entry to have Splunk delete the file once it is forwarded if it comes in all at once (e.g. FTP) .&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 23:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-use-a-universal-forwarder-to-monitor-a/m-p/140645#M28821</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-28T23:16:38Z</dc:date>
    </item>
  </channel>
</rss>

