Thanks - this suggestion helps somewhat.
Tried as suggested and bouncing Splunk, but the indexed data did not change. When I also updated "ignoreolderthan" to go back beyond the Windows last modification date of the log file and again bounced Splunk, then everything in the log file got read in.
However, since then the monitored log file has again been updated (file size has grown, I can view the changed content in Notepad, etc.) but the modification date is still unchanged - and those additional lines have not been indexed by Splunk.
... View more