Monitoring Splunk

Monitoring file without timestamp

habbash
Loves-to-Learn

Hi Splunker;

I have file without timestamp, and Splunk monitoring this file, once any new logs coming to this file, Splunk read all the logs in this file (old and new logs), so how I can to do configuration to Splunk read only the new logs coming to the file.

 

Please help me.

 

Best Regards; 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...