To avoid too much data collection, I would like Splunk to only index a log file following a manual action like clicking on a cell in the search result.
I have already set up the index on the indexer, the class on the deployment-server, but currently it collects every file logs.
2015-06-15 13:40:13 hostname ERROR getdetails gfServerDetails failed /apps/user/tmp/xxxxxxx.tmp.get_details
So what I would like is when clicking on the file name, Splunk goes to read the file and display the result.
Not sure if my request is clear enough. Do not hesitate to request more details.
Thanks for your help.
The indexers/search-head have no control on the forwarders, and also have no knowledge of the list of files available. So you cannot search on log files that have not yet be indexed.
So your question looks more like an Enhancement Request.
Tracks to try manually :
View solution in original post
The oneshot command could be useful, I will try that.