<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor - File&amp; directories  - file is not getting updated on recent changes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340455#M62802</link>
    <description>&lt;P&gt;Hi &lt;BR /&gt;
nickhillscpl,&lt;BR /&gt;
In my case some fields of earlier events can have changed value . Will splunk re-run searches on those too.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Dec 2017 06:18:56 GMT</pubDate>
    <dc:creator>alfiyashaikh</dc:creator>
    <dc:date>2017-12-15T06:18:56Z</dc:date>
    <item>
      <title>monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340451#M62798</link>
      <description>&lt;P&gt;I have added file ABC.csv from my local directory and uploaded it on splunk by "monitor" adding data option.&lt;/P&gt;

&lt;P&gt;source="C:\Alfiya\TASKS\MACRO_in_splunk\cases_and_feedback lookup\PICKUP_FOLDER\ABC.csv" host="P2B-H7TN882" index="test" sourcetype="csv"&lt;/P&gt;

&lt;P&gt;after i run a search on my file it gives me 2000 events as result.&lt;/P&gt;

&lt;P&gt;I deleted some data from ABC.csv file in my local machine . so when i rerun the search on my splunk instance , i still get 2000 event as result.&lt;BR /&gt;
 I should ideally get less number of event now as i have reduced the data.&lt;/P&gt;

&lt;P&gt;I Don't know where I am going wrong or may be I am not properly using "Monitor" adding data option&lt;/P&gt;

&lt;P&gt;Please guide me through .&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:14:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340451#M62798</guid>
      <dc:creator>alfiyashaikh</dc:creator>
      <dc:date>2020-09-29T17:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340452#M62799</link>
      <description>&lt;P&gt;That's not really how it works.&lt;/P&gt;

&lt;P&gt;Monitoring a file means watching it for &lt;STRONG&gt;new&lt;/STRONG&gt; data. Think about a log file - new lines are added to the end, and this is what Splunk is monitoring for.&lt;/P&gt;

&lt;P&gt;If you remove lines from the file (or even delete the file entirely) this data is not removed from Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 13:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340452#M62799</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-14T13:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340453#M62800</link>
      <description>&lt;P&gt;If you want index new data, try replace the file with new data and not delete it.&lt;/P&gt;

&lt;P&gt;If you want delete data from Splunk using :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Your Search from data delete" | delete
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 14 Dec 2017 16:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340453#M62800</guid>
      <dc:creator>julio19</dc:creator>
      <dc:date>2017-12-14T16:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340454#M62801</link>
      <description>&lt;P&gt;Hi &lt;BR /&gt;
nickhillscpl,&lt;/P&gt;

&lt;P&gt;In my case some fields of earlier events can have changed value . Will splunk re-run searches on those too.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 06:17:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340454#M62801</guid>
      <dc:creator>alfiyashaikh</dc:creator>
      <dc:date>2017-12-15T06:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340455#M62802</link>
      <description>&lt;P&gt;Hi &lt;BR /&gt;
nickhillscpl,&lt;BR /&gt;
In my case some fields of earlier events can have changed value . Will splunk re-run searches on those too.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 06:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340455#M62802</guid>
      <dc:creator>alfiyashaikh</dc:creator>
      <dc:date>2017-12-15T06:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340456#M62803</link>
      <description>&lt;P&gt;Hi alfiyashaikh&lt;/P&gt;

&lt;P&gt;If you reread the whole file, yes. Only then are new values in your index.&lt;/P&gt;

&lt;P&gt;But as julio19 mentioned better to delete the old data by adding the | delete&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
    source="C:\Alfiya\TASKS\MACRO_in_splunk\cases_and_feedback lookup\PICKUP_FOLDER\ABC.csv" host="P2B-H7TN882" index="test" | delete&lt;BR /&gt;
&lt;/CODE&gt;&lt;BR /&gt;
This will reduce duplicate data also any confusion about different named keys for the same values.&lt;/P&gt;

&lt;P&gt;but you have to give yourself the &lt;STRONG&gt;can_delete&lt;/STRONG&gt; role (capability delete_by_keyword)  even when you are an admin. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340456#M62803</guid>
      <dc:creator>Elsurion</dc:creator>
      <dc:date>2020-09-29T17:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340457#M62804</link>
      <description>&lt;P&gt;It seems to me you might be better off getting the data another way.&lt;/P&gt;

&lt;P&gt;option 1:&lt;BR /&gt;
Where is the data to start with - it sounds like the CSV is an export or a report of some kind. If this data is in a database to start with, maybe you could use DBX to take the data straight from source?&lt;/P&gt;

&lt;P&gt;option 2:&lt;BR /&gt;
Use a external tool to pre-process your csv file, and send the results to splunk. &lt;BR /&gt;
An example might be a python (or even bash) script which monitors the file and reports any lines which have been changed, which you can setup as a scripted input.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;is probably more robust, 2 is probably easier/faster&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 15 Dec 2017 10:16:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340457#M62804</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-15T10:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: monitor - File&amp; directories  - file is not getting updated on recent changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340458#M62805</link>
      <description>&lt;P&gt;Super quick and inelegant way, more to illustrate the concept that a working example!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#!/bin/bash

#set the next line to the name of your input file
inputFile="ABC.csv"

#create a history file to compare against next run
historyFile="history"

#compare the two files, and look for any lines which have changed. On first run, output everything
d=$(diff -N $inputFile $historyFile)

#copy the new file to the history file
cp $inputFile $historyFile

#write any changes to stdout so splunk can read them
echo $d
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 15 Dec 2017 10:45:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/monitor-File-directories-file-is-not-getting-updated-on-recent/m-p/340458#M62805</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-15T10:45:18Z</dc:date>
    </item>
  </channel>
</rss>

