I have a dashboard where users can add comments to a .csv lookup file. The comments are only related to the day that they are added. I would like to be able to clear down the .csv on a daily basis (around midnight). Is there a way that I can do this using Splunk to keep all the code in one place?
I plan to use the 'collect' command to send the contents to an index prior to removing all the entries in whatever way is possible.
I have tried using outputlookup but only succeeded in writing blank lines to the .csv, not overwriting or removing the contents.