<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If I have a monitored log file with lines that are overwritten rather than appended, will this cause any problems to indexing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162448#M32971</link>
    <description>&lt;P&gt;&lt;A href="http://www.webadminblog.com/index.php/splunk-best-practices/"&gt;www.webadminblog.com/index.php/splunk-best-practices/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;take a look on th 4th paragraph. &lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2015 01:09:27 GMT</pubDate>
    <dc:creator>stephane_cyrill</dc:creator>
    <dc:date>2015-04-24T01:09:27Z</dc:date>
    <item>
      <title>If I have a monitored log file with lines that are overwritten rather than appended, will this cause any problems to indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162445#M32968</link>
      <description>&lt;P&gt;Suppose I am monitoring a file that has 10 lines in it. These lines are already sent to splunk.&lt;BR /&gt;
Now, if I overwrite this file to have just 5 lines (in other words, my logwriter cleans the log file every time and write some new lines in it - we are reusing the log file that is being monitored)&lt;/P&gt;

&lt;P&gt;Will this cause any problems to splunk indexing?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 00:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162445#M32968</guid>
      <dc:creator>venkat_d</dc:creator>
      <dc:date>2015-03-03T00:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: If I have a monitored log file with lines that are overwritten rather than appended, will this cause any problems to indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162446#M32969</link>
      <description>&lt;P&gt;Hi venkat;&lt;/P&gt;

&lt;P&gt;If when you added your file to splunk, you have choose to upload the file, any time that you'll have updates for that file, you'll need to re-indexing the new file for splunk to take care of the update.&lt;/P&gt;

&lt;P&gt;But if you choose to monitor the file (continuously index data from file and directory), you'll not need to re-index your file; you'll just need to overwrite the old file by the new file at the same location.&lt;BR /&gt;
&lt;STRONG&gt;NB:&lt;/STRONG&gt; The new file most have the same name like the old file.&lt;/P&gt;

&lt;P&gt;In your case, choose the option that correspond to your needs.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 08:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162446#M32969</guid>
      <dc:creator>NOUMSSI</dc:creator>
      <dc:date>2015-03-18T08:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: If I have a monitored log file with lines that are overwritten rather than appended, will this cause any problems to indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162447#M32970</link>
      <description>&lt;P&gt;here is two scenario for you:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The file is deleted or truncated and new data is
rewritten from the start; or&lt;/LI&gt;
&lt;LI&gt;The file is written over the beginning with the
same old contents up to the point where it was
before, then a couple of new lines are added.
In the first case, Splunk will have no problems
detecting the new data. In the second case, unless the
old data is written faster than Splunk can detect that it
has been changed/deleted, it will probably wind up
double-indexing the old data. If the old file is
rewritten fast enough (or moved/renamed over the old
one) then there won't be any problems&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 24 Apr 2015 01:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162447#M32970</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-04-24T01:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: If I have a monitored log file with lines that are overwritten rather than appended, will this cause any problems to indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162448#M32971</link>
      <description>&lt;P&gt;&lt;A href="http://www.webadminblog.com/index.php/splunk-best-practices/"&gt;www.webadminblog.com/index.php/splunk-best-practices/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;take a look on th 4th paragraph. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 01:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-a-monitored-log-file-with-lines-that-are-overwritten/m-p/162448#M32971</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-04-24T01:09:27Z</dc:date>
    </item>
  </channel>
</rss>

