Unfortunately, I need to monitor a whole directory.
In the mean time, I've found a work-around. Every couple of minutes - 'touch' all the files in the directory. It seems to work, since trying that on files which Splunk reported that it cannot read, cause it to read, index and delete them from the directory.
the equivalent for the linux 'touch' in windows is:
copy /b +,,
... View more