Getting Data In

Configure inputs.conf to reindex file every time modification time changes?

horsefez
Motivator

Hi fellow splunkers,

I want to know if I can somehow define a monitor-stanza that reindexes a file (entirely reindexes) each and everytime if the modification time is changed.
So far I found the parameters crcSalt and initCrcLength, but not sure how to use them correctly.

Has anyone an idea how to configure this the right way?

Thanks for your help!

Best regards,
pyro_wood

0 Karma
1 Solution

ddrillic
Ultra Champion
0 Karma

ddrillic
Ultra Champion

A great thread about it at How to reindex data from a forwarder

It says -

alt text

0 Karma

horsefez
Motivator

Cool, thanks ddrillic! 🙂

0 Karma

somesoni2
Revered Legend

How big is the file?

0 Karma

horsefez
Motivator

Hi somesoni2,
I try indexing the splunk.conf files so someone outside of splunk gets alerted when there is a change to them.
I don't think those files are big if it boils down to size.

0 Karma

TStrauch
Communicator

Hi pyro_wood,

i hope this answer will help you. You can set the check_method in props.conf source stanza, to achieve your solution.

https://answers.splunk.com/answers/61006/file-system-monitoring-of-text-files-that-are-overwritten.h...

regards

0 Karma

horsefez
Motivator

Thanks! 🙂
But the docs you are refering to are very old and not relevant anymore

0 Karma

TStrauch
Communicator

Hi, the props.conf link refers to the latest version of props.conf 😉 and the postet link props.conf and inputs.conf do the same 😉

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...