<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reindex file with same data but different timestamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Reindex-file-with-same-data-but-different-timestamp/m-p/411076#M173601</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
If you want to reindex your data then your will have to add crcSalt in your inputs.conf.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;By default, the input only performs CRC checks against the first 256
  bytes of a file. This behavior prevents the input from indexing the same
  file twice, even though you might have renamed it, as with rolling log
  files, for example. Because the CRC is based on only the first
  few lines of the file, it is possible for legitimately different files
  to have matching CRCs, particularly if they have identical headers.&lt;/LI&gt;
&lt;LI&gt;If set, string is added to the CRC.&lt;/LI&gt;
&lt;LI&gt;If set to the literal string "SOURCE" (including the angle brackets), the
full directory path to the source file is added to the CRC. This ensures
that each file being monitored has a unique CRC. When crcSalt is invoked,
it is usually set to SOURCE.&lt;/LI&gt;
&lt;LI&gt;Be cautious about using this setting with rolling log files; it could lead
to the log file being re-indexed after it has rolled.&lt;/LI&gt;
&lt;LI&gt;In many situations, initCrcLength can be used to achieve the same goals.&lt;/LI&gt;
&lt;LI&gt;Default: empty string. &lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 17 Jan 2019 12:03:06 GMT</pubDate>
    <dc:creator>nikita_p</dc:creator>
    <dc:date>2019-01-17T12:03:06Z</dc:date>
    <item>
      <title>Reindex file with same data but different timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reindex-file-with-same-data-but-different-timestamp/m-p/411075#M173600</link>
      <description>&lt;P&gt;There is a file which has same data but file is deleted after few hours and placed again with same data but different timestamp. Splunk has indexed the data once but I want an alert to be triggered whenever the timestamp of the file has changed. Since the file is not getting indexed again I am unable to take care of the same. Anything that can be done to solve this?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 11:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reindex-file-with-same-data-but-different-timestamp/m-p/411075#M173600</guid>
      <dc:creator>AnmolKohli</dc:creator>
      <dc:date>2019-01-17T11:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reindex file with same data but different timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Reindex-file-with-same-data-but-different-timestamp/m-p/411076#M173601</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
If you want to reindex your data then your will have to add crcSalt in your inputs.conf.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;By default, the input only performs CRC checks against the first 256
  bytes of a file. This behavior prevents the input from indexing the same
  file twice, even though you might have renamed it, as with rolling log
  files, for example. Because the CRC is based on only the first
  few lines of the file, it is possible for legitimately different files
  to have matching CRCs, particularly if they have identical headers.&lt;/LI&gt;
&lt;LI&gt;If set, string is added to the CRC.&lt;/LI&gt;
&lt;LI&gt;If set to the literal string "SOURCE" (including the angle brackets), the
full directory path to the source file is added to the CRC. This ensures
that each file being monitored has a unique CRC. When crcSalt is invoked,
it is usually set to SOURCE.&lt;/LI&gt;
&lt;LI&gt;Be cautious about using this setting with rolling log files; it could lead
to the log file being re-indexed after it has rolled.&lt;/LI&gt;
&lt;LI&gt;In many situations, initCrcLength can be used to achieve the same goals.&lt;/LI&gt;
&lt;LI&gt;Default: empty string. &lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 17 Jan 2019 12:03:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Reindex-file-with-same-data-but-different-timestamp/m-p/411076#M173601</guid>
      <dc:creator>nikita_p</dc:creator>
      <dc:date>2019-01-17T12:03:06Z</dc:date>
    </item>
  </channel>
</rss>

