Hi,
I can see that Splunk can load data into indexes in a twofold manner (batch vs rising), the latter of which loads only new data. Despite this, Splunk does not react to the deletion and/or updates of the data set that had been already uploaded. Is there a way to configure the data source so that if I make changes to data, they're reflected in an index?
Many Thanks.
... View more