<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to access Date Partitioned files in HDFS dynamically using virtual index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-access-Date-Partitioned-files-in-HDFS-dynamically-using/m-p/246285#M189089</link>
    <description>&lt;P&gt;Hi sdaruna&lt;/P&gt;

&lt;P&gt;You should define your virtual index to include subfolders recursively and define the time as part of the file source path. You can then control the data returned in Splunk searches by using the Splunk time picker (2016-01-21)&lt;/P&gt;

&lt;P&gt;Path to files in HDFS:&lt;BR /&gt;
/bla/bla/bla&lt;/P&gt;

&lt;P&gt;Time capturing regex:&lt;BR /&gt;
/bla/bla/bla/\d+&lt;/P&gt;

&lt;P&gt;Time format:&lt;BR /&gt;
yyMMdd&lt;/P&gt;

&lt;P&gt;The docs for this is here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Hunk/latest/Hunk/Addavirtualindex"&gt;http://docs.splunk.com/Documentation/Hunk/latest/Hunk/Addavirtualindex&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this is the answer you were looking for, please mark it as Answered. &lt;/P&gt;

&lt;P&gt;j&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2016 07:10:12 GMT</pubDate>
    <dc:creator>jbjerke_splunk</dc:creator>
    <dc:date>2016-01-26T07:10:12Z</dc:date>
    <item>
      <title>How to access Date Partitioned files in HDFS dynamically using virtual index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-access-Date-Partitioned-files-in-HDFS-dynamically-using/m-p/246284#M189088</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I have hdfs folders as below. &lt;/P&gt;

&lt;P&gt;/bla/bla/bla/20160121&lt;BR /&gt;
/bla/bla/bla/20160122&lt;BR /&gt;
/bla/bla/bla/20160123&lt;/P&gt;

&lt;P&gt;How to access the data matched in any specific date only for a given query.? lets say, i would like to get data from 20160121 folder only. I do not want to create one virtual index for each folder, coz we gonna have date for all 365 days in a year.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2016 19:04:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-access-Date-Partitioned-files-in-HDFS-dynamically-using/m-p/246284#M189088</guid>
      <dc:creator>sdaruna</dc:creator>
      <dc:date>2016-01-24T19:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to access Date Partitioned files in HDFS dynamically using virtual index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-access-Date-Partitioned-files-in-HDFS-dynamically-using/m-p/246285#M189089</link>
      <description>&lt;P&gt;Hi sdaruna&lt;/P&gt;

&lt;P&gt;You should define your virtual index to include subfolders recursively and define the time as part of the file source path. You can then control the data returned in Splunk searches by using the Splunk time picker (2016-01-21)&lt;/P&gt;

&lt;P&gt;Path to files in HDFS:&lt;BR /&gt;
/bla/bla/bla&lt;/P&gt;

&lt;P&gt;Time capturing regex:&lt;BR /&gt;
/bla/bla/bla/\d+&lt;/P&gt;

&lt;P&gt;Time format:&lt;BR /&gt;
yyMMdd&lt;/P&gt;

&lt;P&gt;The docs for this is here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Hunk/latest/Hunk/Addavirtualindex"&gt;http://docs.splunk.com/Documentation/Hunk/latest/Hunk/Addavirtualindex&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this is the answer you were looking for, please mark it as Answered. &lt;/P&gt;

&lt;P&gt;j&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2016 07:10:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-access-Date-Partitioned-files-in-HDFS-dynamically-using/m-p/246285#M189089</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2016-01-26T07:10:12Z</dc:date>
    </item>
  </channel>
</rss>

