<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring Folders in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35086#M6352</link>
    <description>&lt;P&gt;The second half of &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Howlogfilerotationishandled" rel="nofollow"&gt;this page&lt;/A&gt; might be useful in understanding how Splunk decides whether a file is new/updated. Might not help, just throwing it out there...&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jan 2011 23:26:47 GMT</pubDate>
    <dc:creator>vaijpc</dc:creator>
    <dc:date>2011-01-28T23:26:47Z</dc:date>
    <item>
      <title>Monitoring Folders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35085#M6351</link>
      <description>&lt;P&gt;Splunk is monitoring several folders, but upon careful inspection I've noticed that it seems to be "skipping" files here and there.  What's the easiest way to "make" Splunk go back and read in those files?&lt;/P&gt;

&lt;P&gt;Thanks,
-S.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2011 22:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35085#M6351</guid>
      <dc:creator>sondradotcom</dc:creator>
      <dc:date>2011-01-28T22:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Folders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35086#M6352</link>
      <description>&lt;P&gt;The second half of &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Howlogfilerotationishandled" rel="nofollow"&gt;this page&lt;/A&gt; might be useful in understanding how Splunk decides whether a file is new/updated. Might not help, just throwing it out there...&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2011 23:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35086#M6352</guid>
      <dc:creator>vaijpc</dc:creator>
      <dc:date>2011-01-28T23:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Folders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35087#M6353</link>
      <description>&lt;P&gt;Ah! Helpful.  So, if I salt the CRC with, say, &lt;SOURCE&gt;, will it go back and re-index everything, including the files that are already indexed perfectly well?&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;-S.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2011 01:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35087#M6353</guid>
      <dc:creator>sondradotcom</dc:creator>
      <dc:date>2011-01-29T01:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Folders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35088#M6354</link>
      <description>&lt;P&gt;That sounds like it might work... never tried it myself though so only one way to find out!&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2011 18:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-Folders/m-p/35088#M6354</guid>
      <dc:creator>vaijpc</dc:creator>
      <dc:date>2011-01-31T18:25:19Z</dc:date>
    </item>
  </channel>
</rss>

