Dear all,
Is it possible to index a complete file every 24 hours, even if it has no change?
Thanks in advance for the help.
Hi @msilvareal ,
Did you have a chance to check out any answers? If any work, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.
Thanks for posting!
Splunk tries to avoid re-indexing the same unchanged file. This saves your license costs. If you really want to re-index the same data, one slightly ugly approach is to schedule a scripted input to run every 24 hours. The script can be a few lines of python code that read the file and write it to stdout, which Splunk will index.