We have a process that writes log lines to a log file. Every 15 min the entire log file is overwritten. If there are new lines, those are added. Old lines are retained.
We want the Heavy Forwarder to send to Splunk only the new lines, even though the entire file has got overwritten. Is that possible?