Getting Data In

Changing inputs.conf to include previously scanned files

tyronetv
Communicator

When initially set up my splunk install is set to capture only the most recent version of a log:

/path/to/log/dir/logfile.

Well, sometimes, due to maintenance, etc., Splunk is shut off and when restarted I have to go through the process of reloading (via oneshot) the data from logfile.1 logfile.2 logfile.3 . . . to get caught up.

On systems I've set up, I just have inputs.conf configured for /path/to/log/dir with a whitelist on logfile*$

What will happen if I change the previous configuration? Will it re-index all the previous logfile.\d+$ files or is it self-aware enough to not do that?

Tags (2)
0 Karma
1 Solution
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...