Getting Data In

Splunk Input from S3


I am quite new to the Splunk currently Working on getting data from S3 file into Splunk.

File Constraints ->

1) File will be replaced daily with updated file having previous and new data.

2) there will be field with - timestamp that can be used to find out which rows are new or updated.


Is it possible to configure splunk to get only new data from that file on daily basis. What configuration needs to be updated.


Labels (3)
0 Karma