Getting Data In

How to monitor and index html reports generated daily, even if there are no changes?

Shark2112
Communicator

Hey.

My antivirus generates 4 html reports every day in a folder, but I see a different number of events every time in Splunk (from 2 to 4). I think it's because reports may be same, so Splunk doesn't make new events. It does create dates for these reports every time.

inputs.conf on forwarder:

[monitor://C:\splrpt\*.html]
disabled = false
sourcetype = kavsrc
index = kav
0 Karma
1 Solution

Shark2112
Communicator

increasing initCrcLength is work fine, but i dont understand why, it's just search changes from start, so how work syslog for example, it's adding strings to end

View solution in original post

0 Karma

Shark2112
Communicator

increasing initCrcLength is work fine, but i dont understand why, it's just search changes from start, so how work syslog for example, it's adding strings to end

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...