What is the difference between using Spool vs OneShot CLI commands? Unfortunately I'm unable to install UFs or directly poll the logs and need to index tar.gz. Is there a performance benefit? Does using spool allow the indexer Splunk server to index the data in the background?
Hi
Those are described here https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/MonitorfilesanddirectoriesusingtheCLI
check also this https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Monitorfilesanddirectories
r. Ismo