I have a Splunk UF monitoring many directories on a rsyslog (receiver) server.
One of the directories populated with logs as expected.
However, the input stanza had the incorrect sourcetype and the data/logs did not index.
Now after removing the sourcetype, I need to reset the UF to re-monitor the log files in that single directory "only". I do NOT want to re-index everything the UF monitors.
Please advise the best way to handle this...
View solution in original post