<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log File Rotation in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-File-Rotation/m-p/20528#M3003</link>
    <description>&lt;P&gt;It will not reindex your file. Splunk will not do this by default. Normally, it identifies a file using a hash of the first 256 bytes of the file content, and not the file path/name. (This can be overridden.) However, do note that if you rename and &lt;EM&gt;compress&lt;/EM&gt; the file, it will be reindexed, but you can suppress this by blacklisting compressed files by the name.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jan 2011 05:26:04 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2011-01-05T05:26:04Z</dc:date>
    <item>
      <title>Log File Rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-File-Rotation/m-p/20527#M3002</link>
      <description>&lt;P&gt;When splunk is watching a directory for log files will it reindex a file that gets rotated?
I am trying to make sure that some of my logs are not getting indexed twice.&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;P&gt;file1.log gets changed to file1.log12212010 service creates new file1.log and continues logging.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2011 05:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-File-Rotation/m-p/20527#M3002</guid>
      <dc:creator>snapfinger</dc:creator>
      <dc:date>2011-01-05T05:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Log File Rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-File-Rotation/m-p/20528#M3003</link>
      <description>&lt;P&gt;It will not reindex your file. Splunk will not do this by default. Normally, it identifies a file using a hash of the first 256 bytes of the file content, and not the file path/name. (This can be overridden.) However, do note that if you rename and &lt;EM&gt;compress&lt;/EM&gt; the file, it will be reindexed, but you can suppress this by blacklisting compressed files by the name.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2011 05:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-File-Rotation/m-p/20528#M3003</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-01-05T05:26:04Z</dc:date>
    </item>
  </channel>
</rss>

