Hello,
My problem is simple to explain: I have an app that generates logs that are written whenever a new action is performed.
The problem is, when the session is over, the first line of that log is changed to include the close time of the session, which makes splunk REINDEX everything on the log.
Any ideas?
Thanks
↧