Getting Data In

Reindex linux log file

TheBravoSierra
Path Finder

I need to index a file: /var/log/file.txt. This file runs every day, but sometimes the content doesn't change. This leaves me with no events on days that remain the same. I need it to index every time the timestamp changes on the file. I believe I need to add crcSalt =<SOURCE> to the inputs.conf in order to reindex it. However, my inputs monitors all files in /var/log. So if I add that to that input monitor, it would likely apply to all files in var log reindexing them all every time. Something I don't want. How can I reindex just this file daily while leaving the other files in the directory unchanged? 

Many thanks

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Create a separate inputs.conf stanza for /var/log/file.txt with crcSalt. Then blacklist file.txt from original /var/log monitoring stanza.

View solution in original post

somesoni2
Revered Legend

Create a separate inputs.conf stanza for /var/log/file.txt with crcSalt. Then blacklist file.txt from original /var/log monitoring stanza.

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...