<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor vs Batch Job for inputting data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-vs-Batch-Job-for-inputting-data/m-p/185495#M37141</link>
    <description>&lt;P&gt;Usually Batch input is used for large historical data. It is not a good practice for small and continuously updating files.&lt;/P&gt;

&lt;P&gt;Consider a case where i faced using batch input i fed splunk a large files and folders and in between the license limit was reached and stopped splunk to wait 24 hours and later i couldn't start indexing from where it stopped because the file was deleted. Due to &lt;CODE&gt;move_policy = sinkhole&lt;/CODE&gt; policy that is mandatory for batch inputs.  And I had no clue till what point the data was indexed all i did was i flushed the index and reindex whole data using monitor.&lt;/P&gt;

&lt;P&gt;It depends on the size of the data and its availability you should be able to choose the best one.&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2015 14:24:27 GMT</pubDate>
    <dc:creator>krish3</dc:creator>
    <dc:date>2015-05-11T14:24:27Z</dc:date>
    <item>
      <title>Monitor vs Batch Job for inputting data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-vs-Batch-Job-for-inputting-data/m-p/185494#M37140</link>
      <description>&lt;P&gt;Currently, my preProd environment is set up to monitor logs from 100-150 servers with the monitor stanza in inputs.conf.  I have been asked to research changing all these stanza to batch jobs because the pre-Prod forwarders apparently stop running from an overload of the saved files on them.  I was wondering if anyone has had to tackle this before or if there is a better way of doing this.  I figure the forwarder admins don't want to set up jobs on their own servers so they want Splunk to delete the files once indexed. &lt;/P&gt;

&lt;P&gt;Assistance would be appreciated.  Thank you &lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2015 14:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-vs-Batch-Job-for-inputting-data/m-p/185494#M37140</guid>
      <dc:creator>JoeSco27</dc:creator>
      <dc:date>2015-05-11T14:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor vs Batch Job for inputting data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-vs-Batch-Job-for-inputting-data/m-p/185495#M37141</link>
      <description>&lt;P&gt;Usually Batch input is used for large historical data. It is not a good practice for small and continuously updating files.&lt;/P&gt;

&lt;P&gt;Consider a case where i faced using batch input i fed splunk a large files and folders and in between the license limit was reached and stopped splunk to wait 24 hours and later i couldn't start indexing from where it stopped because the file was deleted. Due to &lt;CODE&gt;move_policy = sinkhole&lt;/CODE&gt; policy that is mandatory for batch inputs.  And I had no clue till what point the data was indexed all i did was i flushed the index and reindex whole data using monitor.&lt;/P&gt;

&lt;P&gt;It depends on the size of the data and its availability you should be able to choose the best one.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2015 14:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-vs-Batch-Job-for-inputting-data/m-p/185495#M37141</guid>
      <dc:creator>krish3</dc:creator>
      <dc:date>2015-05-11T14:24:27Z</dc:date>
    </item>
  </channel>
</rss>

