- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Intermittent text file data collection is not possible.
Initially, it is a collection of csv file data.
After that, if you change only a few characters in the csv, you cannot collect them intermittently.
Which part should I check?
- setting
[monitor://D:\Space\Config*File\Devicenet_Config.csv]
disabled = 0
host = HOST_NAME
index = FDC_MainUtility
sourcetype = FDCField
crcSalt = <SOURCE>
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


What you describe sounds normal. Splunk will not necessarily notice arbitrary character changes in a file. If it does notice then it will re-index the entire file - possibly resulting in duplicate data. Splunk expects new data to be written to the end of the file.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


What you describe sounds normal. Splunk will not necessarily notice arbitrary character changes in a file. If it does notice then it will re-index the entire file - possibly resulting in duplicate data. Splunk expects new data to be written to the end of the file.
If this reply helps you, Karma would be appreciated.
