<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor latest file only in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84685#M1041</link>
    <description>&lt;P&gt;The easiest way would be to monitor a separate folder and let the script place a symlink for the latest file there. &lt;/P&gt;</description>
    <pubDate>Fri, 05 Nov 2010 17:52:12 GMT</pubDate>
    <dc:creator>ziegfried</dc:creator>
    <dc:date>2010-11-05T17:52:12Z</dc:date>
    <item>
      <title>monitor latest file only</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84684#M1040</link>
      <description>&lt;P&gt;I write a script to blacklist the oldest file but splunk don't reload inputs.conf until someone restart the services but it is not acceptable in my case. Do there are any options that control splunk to monitor only latest file or some rule like abandon oldest file when I need to monitor a folder that contains over thousands of file.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2010 17:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84684#M1040</guid>
      <dc:creator>katalinali</dc:creator>
      <dc:date>2010-11-05T17:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: monitor latest file only</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84685#M1041</link>
      <description>&lt;P&gt;The easiest way would be to monitor a separate folder and let the script place a symlink for the latest file there. &lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2010 17:52:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84685#M1041</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2010-11-05T17:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: monitor latest file only</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84686#M1042</link>
      <description>&lt;P&gt;The main caveat being sure you know when the latest file is 'done' and splunk has completely indexed it before redoing the symlink.  Perhaps a good compromise might be to keep a symlink to the most current log and the one most-previous log.  That way, Splunk can still have access to the prior 'latest' file right around the time of switchover.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2010 21:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84686#M1042</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2010-11-05T21:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: monitor latest file only</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84687#M1043</link>
      <description>&lt;P&gt;It is windows platform and I don't have the right to control where the file should be placed. It may not work for me&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2010 09:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/monitor-latest-file-only/m-p/84687#M1043</guid>
      <dc:creator>katalinali</dc:creator>
      <dc:date>2010-11-08T09:36:46Z</dc:date>
    </item>
  </channel>
</rss>

