I have multiple monitored csv files that are created every day at different times on a single server with a Universal Forwarder. Old files are deleted and completely new files are created. Each file is indexed when created and then again at 05:30 am the next day causing duplicate data.
Looking through Splunk>answers, I found where I should add the crcSalt = line in the [monitor] section of inputs.conf. I did this for one of the files and the file is still being indexed twice.
What else should I do to stop the second indexing?
I do find it interesting that the second indexing for these files happen at the same time. Is there some config that sets that time? Just wondering.
Thanks for any help provided.
Scott
↧