<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring file without timestamp in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-file-without-timestamp/m-p/537381#M4747</link>
    <description>&lt;P&gt;Hi Splunker;&lt;/P&gt;&lt;P&gt;I have file without timestamp, and Splunk monitoring this file, once any new logs coming to this file, Splunk read all the logs in this file (old and new logs), so how I can to do configuration to Splunk read only the new logs coming to the file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jan 2021 10:02:31 GMT</pubDate>
    <dc:creator>habbash</dc:creator>
    <dc:date>2021-01-27T10:02:31Z</dc:date>
    <item>
      <title>Monitoring file without timestamp</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-file-without-timestamp/m-p/537381#M4747</link>
      <description>&lt;P&gt;Hi Splunker;&lt;/P&gt;&lt;P&gt;I have file without timestamp, and Splunk monitoring this file, once any new logs coming to this file, Splunk read all the logs in this file (old and new logs), so how I can to do configuration to Splunk read only the new logs coming to the file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 10:02:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-file-without-timestamp/m-p/537381#M4747</guid>
      <dc:creator>habbash</dc:creator>
      <dc:date>2021-01-27T10:02:31Z</dc:date>
    </item>
  </channel>
</rss>

