Getting Data In

Splunk Input from S3

saty586
Explorer

I am quite new to the Splunk currently Working on getting data from S3 file into Splunk.

File Constraints ->

1) File will be replaced daily with updated file having previous and new data.

2) there will be field with - timestamp that can be used to find out which rows are new or updated.

 

Is it possible to configure splunk to get only new data from that file on daily basis. What configuration needs to be updated.

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...