Getting Data In

Configure universal forwarder to forward files at a particular time

termcap
Path Finder

Hi Splunkers,

 

I had two questions with regards to the universal forwarder and  a csv file.

1. Is it possible to configure the universal forwarder to forward a file at 11PM every night irrespective of whether the file has changed or not. (I understand that the whole file will be forwarded each night)

2. How can I force the universal forwarder to resend the whole file ? Can changing the timestamp do the trick ?

Thanks,

Termcap

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

1.  There is no such feature.  If you have a compelling use case for it, submit it at https://ideas.splunk.com.

2. Changing the timestamp may make Splunk take another look at the file, but it quickly will realize it's processed it before and refuse to do so again.  To get a UF to re-process a file you must make it forget it's done so already by deleting the fishbucket.  See https://docs.splunk.com/Documentation/Splunk/8.1.1/Troubleshooting/CommandlinetoolsforusewithSupport...

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

1.  There is no such feature.  If you have a compelling use case for it, submit it at https://ideas.splunk.com.

2. Changing the timestamp may make Splunk take another look at the file, but it quickly will realize it's processed it before and refuse to do so again.  To get a UF to re-process a file you must make it forget it's done so already by deleting the fishbucket.  See https://docs.splunk.com/Documentation/Splunk/8.1.1/Troubleshooting/CommandlinetoolsforusewithSupport...

---
If this reply helps you, Karma would be appreciated.
0 Karma

termcap
Path Finder

What you have stated is the default behavior of the UF.

I was I was able to get the UF to re-process the whole file by adding random junk characters and enabling the crcSalt = <SOURCE> for the file.

Then exclude those junk characters using transforms.conf.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...