I need to read csv files *dynamically*. That is, every week a new file is added. So every week I need to read an additional file. Is there a way to build an automated dynamic command? I can get the list of all files with rest/servicesNS/-/-/data/lookup-table-files | search title="file*.csv". But what's next?
my current workaround is to build the cmd using the above, and then copying it to the spl line and running it. This is not automatic of course.
All the examples above are for a static list of files.
If your files have more thank 50500 lines, other methods may truncate your events due to subsearch limits. The only what that I have found to pull in multiple CSVs without truncation on any version of Splunk is like this: