Getting Data In

Index only new lines

grivera_kudaw
Explorer

Hi.

I have a requirement of a client, he has a file that indexes every day, but that file is modified at different times, for example modifications to lines 8 and 10000 at 20:00hrs, after modifications of lines 2 and 10100 at 22:00 hrs , Is it possible to index only the lines that have been modified?, at 2:00 am the file not change more.

Tags (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

No, Splunk cannot be configured to monitor individual changes inside a file. Just the entire file, or new lines at the end of a file.

So the only way to do this would be to write some kind of script that detects the changes and writes those to a new file that is monitored by Splunk.

View solution in original post

FrankVl
Ultra Champion

No, Splunk cannot be configured to monitor individual changes inside a file. Just the entire file, or new lines at the end of a file.

So the only way to do this would be to write some kind of script that detects the changes and writes those to a new file that is monitored by Splunk.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...