I have two different file names in the same directory on a forwarder. The problem is, the data for both files are the same, so how do I allow all the events to be indexed on my receiver side?
Monitor individual files instead of the whole directory.
How do i monitor individual files ? Is there an example ?
If the answer by @richgalloway solved your issue, please don't forget to resolve the post by clicking "Accept" directly below his answer. If you're still having issues, please comment with more details.
In your [monitor://] stanza name, put a path to an individual file instead of to a directory. See http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Inputsconf for more.