<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I'm testing splunk, and when I edit my logfiles,  splunk doesn't notice the changes.  Why? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11683#M682</link>
    <description>&lt;P&gt;By default, Splunk detects changes in files by first checking the modification time. &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;If that has changed, it checks the first 256 bytes of the file
&lt;UL&gt;
&lt;LI&gt;If that is different from the last time it saw the file, it will index the file from the beginning.&lt;/LI&gt;
&lt;LI&gt;If it is the same as the last time it saw the file, it will check the last 256 bytes of the file.
&lt;UL&gt;
&lt;LI&gt;If it has changed, Splunk will index new events from the point that previously read.&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thus, if you change the file in the middle, Splunk may detect the modification times, but will not see any change at the beginning or end of the file, and therefore will index any part of the file anew.&lt;/P&gt;</description>
    <pubDate>Sat, 17 Apr 2010 14:25:46 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2010-04-17T14:25:46Z</dc:date>
    <item>
      <title>I'm testing splunk, and when I edit my logfiles,  splunk doesn't notice the changes.  Why?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11682#M681</link>
      <description>&lt;P&gt;I have a test logfile I fed into Splunk:&lt;/P&gt;

&lt;P&gt;Apr 13 10:41:16 support05 kernel: [1815783.556088] usb 2-1: new full speed USB device using uhci_hcd and address 32
Apr 13 10:41:16 support05 kernel: [1815783.699049] usb 2-1: not running at top speed; connect to a high speed hub&lt;/P&gt;

&lt;P&gt;and so on.&lt;/P&gt;

&lt;P&gt;Splunk consumed the file just fine.&lt;/P&gt;

&lt;P&gt;Then I opened the file and overwrote some text in the middle of the file.  Splunk ignored my changes.
Why didn't splunk re-index those lines?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2010 08:52:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11682#M681</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-04-17T08:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: I'm testing splunk, and when I edit my logfiles,  splunk doesn't notice the changes.  Why?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11683#M682</link>
      <description>&lt;P&gt;By default, Splunk detects changes in files by first checking the modification time. &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;If that has changed, it checks the first 256 bytes of the file
&lt;UL&gt;
&lt;LI&gt;If that is different from the last time it saw the file, it will index the file from the beginning.&lt;/LI&gt;
&lt;LI&gt;If it is the same as the last time it saw the file, it will check the last 256 bytes of the file.
&lt;UL&gt;
&lt;LI&gt;If it has changed, Splunk will index new events from the point that previously read.&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thus, if you change the file in the middle, Splunk may detect the modification times, but will not see any change at the beginning or end of the file, and therefore will index any part of the file anew.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2010 14:25:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11683#M682</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-17T14:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: I'm testing splunk, and when I edit my logfiles,  splunk doesn't notice the changes.  Why?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11684#M683</link>
      <description>&lt;P&gt;Fwiw, in 4.1 it's changes in modification time or file size.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2010 15:07:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11684#M683</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-04-17T15:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: I'm testing splunk, and when I edit my logfiles,  splunk doesn't notice the changes.  Why?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11685#M684</link>
      <description>&lt;P&gt;Er, if the last place it was in the file changed, it reindex the whole file too. If they both match and there's new data, it starts from that offset. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2010 15:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-m-testing-splunk-and-when-I-edit-my-logfiles-splunk-doesn-t/m-p/11685#M684</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-04-17T15:08:55Z</dc:date>
    </item>
  </channel>
</rss>

