Alerting

How to index a complete file every 24 hours?

msilvareal
New Member

Dear all,

Is it possible to index a complete file every 24 hours, even if it has no change?

Thanks in advance for the help.

0 Karma

evania
Splunk Employee
Splunk Employee

Hi @msilvareal ,

Did you have a chance to check out any answers? If any work, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.

Thanks for posting!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk tries to avoid re-indexing the same unchanged file. This saves your license costs. If you really want to re-index the same data, one slightly ugly approach is to schedule a scripted input to run every 24 hours. The script can be a few lines of python code that read the file and write it to stdout, which Splunk will index.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...