Getting Data In

Re index of same file with same hash but metadata has changed

diptij
Path Finder

I'm using splunk 8.0.3 on a Linux machine.

It seems a tar.gz file with the same hash gets re indexed by Splunk. 

The only difference that I see is that when I do a 'stat <file>', it shows as Changed.  The Changed means metadata has changed.

Is this behavior documented somewhere?

How do I stop Splunk from re indexing this file if only the metadata changed?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...