<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexing logs as event in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Indexing-logs-as-event/m-p/311402#M5522</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I would like to monitor a file that is being changed every 15 minutes (unique file in the directory) and it is a very large log file (almost 100MB ~ 150MB). I have some questions about that:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is there any way to index just the recent changes and not the entire file? I read something about the followTail setting, however not sure if it is really appropriated;&lt;/LI&gt;
&lt;LI&gt;Index just some lines of the log and not the entire recent changes? Something like: all the recent lines that starts with specific text..Maybe apply here REGEX...&lt;/LI&gt;
&lt;LI&gt;Index the lines of the item 2 as one single event for each repetition... Example the below log file content:&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;S  Sß: (2017120211271200) sending job @&amp;gt;SPOREQ:1597246@DEV:JC15@&amp;lt;'&lt;BR /&gt;
S  2 pages (OTF) printed in 0 seconds, avg. 0.0 pages per sec&lt;BR /&gt;
S  Timeinfo @&amp;gt;SPOREQ:587821@DEV:DS01@&amp;lt;): 0 1 List ( 0 0 0 0 0 0 )&lt;BR /&gt;
S  Sß: (2017120211271300) ....end job @&amp;gt;SPOREQ:1597246@DEV:JC15@&amp;lt;'&lt;BR /&gt;
S  &amp;lt;-- Job @&amp;gt;SPOREQ:1597246@&amp;lt;/1 processed (rc=0) }&lt;/P&gt;

&lt;P&gt;And then have one single line event containing the below information based on the above 5 lines:&lt;BR /&gt;
Start Time | Number of SPOREQ| Printer Name | Quantity of pages | Duration of print | Avg of print | Finish Time | Status&lt;/P&gt;

&lt;P&gt;Many many many thanks for the support!&lt;BR /&gt;
Danillo Pavan&lt;/P&gt;</description>
    <pubDate>Sun, 03 Dec 2017 14:29:46 GMT</pubDate>
    <dc:creator>danillopavan</dc:creator>
    <dc:date>2017-12-03T14:29:46Z</dc:date>
    <item>
      <title>Indexing logs as event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Indexing-logs-as-event/m-p/311402#M5522</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I would like to monitor a file that is being changed every 15 minutes (unique file in the directory) and it is a very large log file (almost 100MB ~ 150MB). I have some questions about that:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is there any way to index just the recent changes and not the entire file? I read something about the followTail setting, however not sure if it is really appropriated;&lt;/LI&gt;
&lt;LI&gt;Index just some lines of the log and not the entire recent changes? Something like: all the recent lines that starts with specific text..Maybe apply here REGEX...&lt;/LI&gt;
&lt;LI&gt;Index the lines of the item 2 as one single event for each repetition... Example the below log file content:&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;S  Sß: (2017120211271200) sending job @&amp;gt;SPOREQ:1597246@DEV:JC15@&amp;lt;'&lt;BR /&gt;
S  2 pages (OTF) printed in 0 seconds, avg. 0.0 pages per sec&lt;BR /&gt;
S  Timeinfo @&amp;gt;SPOREQ:587821@DEV:DS01@&amp;lt;): 0 1 List ( 0 0 0 0 0 0 )&lt;BR /&gt;
S  Sß: (2017120211271300) ....end job @&amp;gt;SPOREQ:1597246@DEV:JC15@&amp;lt;'&lt;BR /&gt;
S  &amp;lt;-- Job @&amp;gt;SPOREQ:1597246@&amp;lt;/1 processed (rc=0) }&lt;/P&gt;

&lt;P&gt;And then have one single line event containing the below information based on the above 5 lines:&lt;BR /&gt;
Start Time | Number of SPOREQ| Printer Name | Quantity of pages | Duration of print | Avg of print | Finish Time | Status&lt;/P&gt;

&lt;P&gt;Many many many thanks for the support!&lt;BR /&gt;
Danillo Pavan&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2017 14:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Indexing-logs-as-event/m-p/311402#M5522</guid>
      <dc:creator>danillopavan</dc:creator>
      <dc:date>2017-12-03T14:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing logs as event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Indexing-logs-as-event/m-p/311403#M5523</link>
      <description>&lt;P&gt;Check out this app:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2864/"&gt;https://splunkbase.splunk.com/app/2864/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2017 17:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Indexing-logs-as-event/m-p/311403#M5523</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-12-03T17:16:41Z</dc:date>
    </item>
  </channel>
</rss>

