trying to find the best solution (approach) to the following issue:
We are monitoring ( via Splunk Universal forwarder ) the file "Assignment_group.csv" , exported daily from Service Now.
It exports assignment_groups and It has department name, team name, team's manager:
"Our department" , "Our Team", "Our Manager".
We ingest it and use it as lookup for assignment groups in our related dashboards.
If file is not changed - Splunk doesn't index it again , it seems, and as a result - our lookup gets empty.
We thought about using [batch://...] to read the same file instead of [monitor://...] but it deletes the source file and we want to keep it for troubleshooting proposes.