Getting Data In
Highlighted

How to monitor and index html reports generated daily, even if there are no changes?

Communicator

Hey.

My antivirus generates 4 html reports every day in a folder, but I see a different number of events every time in Splunk (from 2 to 4). I think it's because reports may be same, so Splunk doesn't make new events. It does create dates for these reports every time.

inputs.conf on forwarder:

[monitor://C:\splrpt\*.html]
disabled = false
sourcetype = kavsrc
index = kav
0 Karma
Highlighted

Re: How to monitor and index html reports generated daily, even if there are no changes?

Communicator

increasing initCrcLength is work fine, but i dont understand why, it's just search changes from start, so how work syslog for example, it's adding strings to end

View solution in original post

0 Karma