We have csv type of data file which is overwritten and with new data appended to the end every night.
I found Splunk load/duplicate all the data again everyday!
As I know crcSalt only check CRC with first few lines of the file. How Splunk works in this case to identify only end of the file has new data?
followTail works for file replace?