Alerting

How to index a complete file every 24 hours?

msilvareal
New Member

Dear all,

Is it possible to index a complete file every 24 hours, even if it has no change?

Thanks in advance for the help.

0 Karma

evania
Splunk Employee
Splunk Employee

Hi @msilvareal ,

Did you have a chance to check out any answers? If any work, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.

Thanks for posting!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk tries to avoid re-indexing the same unchanged file. This saves your license costs. If you really want to re-index the same data, one slightly ugly approach is to schedule a scripted input to run every 24 hours. The script can be a few lines of python code that read the file and write it to stdout, which Splunk will index.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...