Getting Data In

Configure inputs.conf to reindex file every time modification time changes?

horsefez
SplunkTrust
SplunkTrust

Hi fellow splunkers,

I want to know if I can somehow define a monitor-stanza that reindexes a file (entirely reindexes) each and everytime if the modification time is changed.
So far I found the parameters crcSalt and initCrcLength, but not sure how to use them correctly.

Has anyone an idea how to configure this the right way?

Thanks for your help!

Best regards,
pyro_wood

0 Karma
1 Solution

ddrillic
Ultra Champion
0 Karma

ddrillic
Ultra Champion

A great thread about it at How to reindex data from a forwarder

It says -

alt text

0 Karma

horsefez
SplunkTrust
SplunkTrust

Cool, thanks ddrillic! 🙂

0 Karma

somesoni2
Revered Legend

How big is the file?

0 Karma

horsefez
SplunkTrust
SplunkTrust

Hi somesoni2,
I try indexing the splunk.conf files so someone outside of splunk gets alerted when there is a change to them.
I don't think those files are big if it boils down to size.

0 Karma

TStrauch
Communicator

Hi pyro_wood,

i hope this answer will help you. You can set the check_method in props.conf source stanza, to achieve your solution.

https://answers.splunk.com/answers/61006/file-system-monitoring-of-text-files-that-are-overwritten.h...

regards

0 Karma

horsefez
SplunkTrust
SplunkTrust

Thanks! 🙂
But the docs you are refering to are very old and not relevant anymore

0 Karma

TStrauch
Communicator

Hi, the props.conf link refers to the latest version of props.conf 😉 and the postet link props.conf and inputs.conf do the same 😉

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...