Getting Data In

How to monitor and index html reports generated daily, even if there are no changes?

Shark2112
Communicator

Hey.

My antivirus generates 4 html reports every day in a folder, but I see a different number of events every time in Splunk (from 2 to 4). I think it's because reports may be same, so Splunk doesn't make new events. It does create dates for these reports every time.

inputs.conf on forwarder:

[monitor://C:\splrpt\*.html]
disabled = false
sourcetype = kavsrc
index = kav
0 Karma
1 Solution

Shark2112
Communicator

increasing initCrcLength is work fine, but i dont understand why, it's just search changes from start, so how work syslog for example, it's adding strings to end

View solution in original post

0 Karma

Shark2112
Communicator

increasing initCrcLength is work fine, but i dont understand why, it's just search changes from start, so how work syslog for example, it's adding strings to end

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...