Getting Data In

Configure universal forwarder to forward files at a particular time

termcap
Path Finder

Hi Splunkers,

 

I had two questions with regards to the universal forwarder and  a csv file.

1. Is it possible to configure the universal forwarder to forward a file at 11PM every night irrespective of whether the file has changed or not. (I understand that the whole file will be forwarded each night)

2. How can I force the universal forwarder to resend the whole file ? Can changing the timestamp do the trick ?

Thanks,

Termcap

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

1.  There is no such feature.  If you have a compelling use case for it, submit it at https://ideas.splunk.com.

2. Changing the timestamp may make Splunk take another look at the file, but it quickly will realize it's processed it before and refuse to do so again.  To get a UF to re-process a file you must make it forget it's done so already by deleting the fishbucket.  See https://docs.splunk.com/Documentation/Splunk/8.1.1/Troubleshooting/CommandlinetoolsforusewithSupport...

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

1.  There is no such feature.  If you have a compelling use case for it, submit it at https://ideas.splunk.com.

2. Changing the timestamp may make Splunk take another look at the file, but it quickly will realize it's processed it before and refuse to do so again.  To get a UF to re-process a file you must make it forget it's done so already by deleting the fishbucket.  See https://docs.splunk.com/Documentation/Splunk/8.1.1/Troubleshooting/CommandlinetoolsforusewithSupport...

---
If this reply helps you, Karma would be appreciated.
0 Karma

termcap
Path Finder

What you have stated is the default behavior of the UF.

I was I was able to get the UF to re-process the whole file by adding random junk characters and enabling the crcSalt = <SOURCE> for the file.

Then exclude those junk characters using transforms.conf.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...