Pretty new to all this and struggling to understand all the other answers.
I have a cronjob which is extracting CMDB data from service now in json format at 1am each day. its over writes a file. My splunk is monitoring that file. I am expecting 463 results/events. with 90ish fields per event.
I have universal forwarder on a server with internet access which forwards straight to the indexers.