Getting Data In

Splunk Input from S3

saty586
Explorer

I am quite new to the Splunk currently Working on getting data from S3 file into Splunk.

File Constraints ->

1) File will be replaced daily with updated file having previous and new data.

2) there will be field with - timestamp that can be used to find out which rows are new or updated.

 

Is it possible to configure splunk to get only new data from that file on daily basis. What configuration needs to be updated.

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...