We have some customers indexing recovery data from a data outage. These files are 15-30 minutes of logging each. Up to several GB.
Thus far they have been using a standard monitor. But have been pulling files out of the monitor folder. They were "guessing" when Splunk was finished indexing instead of validating with event counts. I have checked, and some of the files were partially ingested.
I want to move them to a batch monitor, but I have questions;
Thanks in advance!
The answer is;
CRC appear to be unique to a monitor. Moving the files in anyway to a new monitor path will result in the re-indexing of that file. No resumes.
The answer is;
CRC appear to be unique to a monitor. Moving the files in anyway to a new monitor path will result in the re-indexing of that file. No resumes.