<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor daily reports in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186517#M37359</link>
    <description>&lt;P&gt;thanks alot&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jun 2014 12:22:29 GMT</pubDate>
    <dc:creator>iceokoli</dc:creator>
    <dc:date>2014-06-03T12:22:29Z</dc:date>
    <item>
      <title>Monitor daily reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186515#M37357</link>
      <description>&lt;P&gt;I need to monitor daily reports with splunk.&lt;BR /&gt;
However the events in the logs are constantly updated throughout the day as each event lasts a whole a day.&lt;BR /&gt;
is there anyway to configure splunk to ensure that it does not parse the event into splunk untill the event has finished?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 10:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186515#M37357</guid>
      <dc:creator>iceokoli</dc:creator>
      <dc:date>2014-06-03T10:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor daily reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186516#M37358</link>
      <description>&lt;P&gt;Hi iceokoli,&lt;/P&gt;

&lt;P&gt;no, this is not possible using a monitor stanza in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.1/admin/Inputsconf"&gt;inputs.conf&lt;/A&gt;. A Monitor stanza will observe the file or directory constantly for new data.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;But ...&lt;/STRONG&gt; &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;you could setup a monitor stanza in inputs.conf to monitor a directory and have some cron driven script that will copy the source file in question into that directory. Splunk will then take only this copied file and index its data.&lt;/LI&gt;
&lt;LI&gt;if you're using an universal forwarder to monitor this file, use a cron job to start and stop Splunk universal forwarder at a curtain time during the day.&lt;/LI&gt;
&lt;LI&gt;you can create some script wrapper that starts the universal forwarder after that event in question is finished ...&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;You see, there are some options but out of the box this will not work the way you asked.&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 11:33:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186516#M37358</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-03T11:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor daily reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186517#M37359</link>
      <description>&lt;P&gt;thanks alot&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 12:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186517#M37359</guid>
      <dc:creator>iceokoli</dc:creator>
      <dc:date>2014-06-03T12:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor daily reports</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186518#M37360</link>
      <description>&lt;P&gt;you're welcome. please mark this as answered by ticking the tick - thx &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 12:32:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-daily-reports/m-p/186518#M37360</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-03T12:32:18Z</dc:date>
    </item>
  </channel>
</rss>

