Getting Data In

Editing an existing data input creates new item

adrianp
Path Finder

When I try to edit an existing data input, it's creating a new one. Shouldn't it just update it?

Tags (3)
1 Solution

Ayn
Legend

No, Splunk is a time-series database - it will read events and assign a timestamp to them once. Events that are indexed will not be modified - if you make changes to existing data that Splunk has already indexed, Splunk will interpret that as that the whole file has changed and its contents needs to be reindexed.

View solution in original post

0 Karma

Ayn
Legend

No, Splunk is a time-series database - it will read events and assign a timestamp to them once. Events that are indexed will not be modified - if you make changes to existing data that Splunk has already indexed, Splunk will interpret that as that the whole file has changed and its contents needs to be reindexed.

0 Karma

Ayn
Legend

Sorry, I obviously misunderstood what you meant. I don't have a good answer for the issue you're having, sorry.

0 Karma

adrianp
Path Finder
0 Karma

adrianp
Path Finder

Um, I don't follow. I'm talking about where you edit Data Inputs and select, File, Events Log, syslog, etc... When I click on one that I created (to edit it because I made a mistake), after I hit save, instead of updating the one I was editing, it just creates a new item.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...