Getting Data In

File and Directory Monitor

PaulEscher
Explorer

We have several files on many workstations and the files are appended to every few minutes. Instead of having a light forwarder on each workstation we would like to copy the files to a central location every 5 minutes or so. As the file names will stay the same, we will overwrite them with newer files (larger) with each batch copy.

Will Splunk know that it has already indexed the first half of each file? Will this work as expected without duplicate entries? Is there a better way to do this?

Thanks, Paul

Tags (1)
0 Karma
1 Solution

Michael_Wilde
Splunk Employee
Splunk Employee

A good discussion around how file monitoring works is in Episode 25 - "The Fishbucket List" of the SplunkTalk Podcast.

View solution in original post

Michael_Wilde
Splunk Employee
Splunk Employee

A good discussion around how file monitoring works is in Episode 25 - "The Fishbucket List" of the SplunkTalk Podcast.

bbingham
Builder

A developer for splunk could attest to this better, but from my understanding splunk pulls the first few lines of the file, ties it to the file name and records a hash for the header, then it indexes the file, and remembers the last line, as long as the header is the same, and the last lines are different, splunk marks the file as changed, and will index the remainder of the file, starting from where it left off. I would assume that as long as your header doesn't change with each new copy of the file, splunk wouldn't have an issue picking up where it left off.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...