- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hello,
I need some help. Icreate a csv file on remote server from a mysql quert.
I forward the csv file from the remote server to splunk.
I can read the data. The csv file is over written each day, it have have only 1 line of
data, or multiple lines of data - it is a list of device that have gon down. If no devices
are down, the the file only has the hearder, and data that says: :No Devices Down:" I only want to see data from the file on the day the file is writtern. The challenge I have is to read only the data in the file for that day. The issue is that splunk indexes the data, so splunk retains the data over time, like I want only 1 day info from the file, but splunk has all the data indexed
How can I return only the data for the day, not for all data in splunk indes?
thanks,
EWHolz
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


There are two things you can do.
1) Change the retention period of the indexed data to one day. If necessary, create a new index dedicated to the CSV data.
2) When searching the CSV data, fetch only the most recent day.
index=foo earliest=-24h
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


There are two things you can do.
1) Change the retention period of the indexed data to one day. If necessary, create a new index dedicated to the CSV data.
2) When searching the CSV data, fetch only the most recent day.
index=foo earliest=-24h
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hello Members and richgallowy,
Thanks for the tip. It has been a while since I have needed to apply my
limited "Splunk" skills, I appreciate this suggestion, and will try it out;.
Regards,
EWHolz
