hi,
I have a monitored directory that is indexed by splunk. I tried removing the files in the directory after they are indexed. Restarted the splunk daemon and I still see the file contents when searched. My question is, can I confirm that I can safely remove those files in that directory that are already indexed without any other consequences ?
thanks
Once files are indexed then data remains in Splunk until it ages out. You no longer need the source file.
Once files are indexed then data remains in Splunk until it ages out. You no longer need the source file.