Alerting

How to index a complete file every 24 hours?

msilvareal
New Member

Dear all,

Is it possible to index a complete file every 24 hours, even if it has no change?

Thanks in advance for the help.

0 Karma

evania
Splunk Employee
Splunk Employee

Hi @msilvareal ,

Did you have a chance to check out any answers? If any work, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help you.

Thanks for posting!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk tries to avoid re-indexing the same unchanged file. This saves your license costs. If you really want to re-index the same data, one slightly ugly approach is to schedule a scripted input to run every 24 hours. The script can be a few lines of python code that read the file and write it to stdout, which Splunk will index.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...