Hi,
each day, I download new logs in directories which are monitored.
I would like to know how to force Splunk to add these new logs just after their downloading.
PS : I don't want to re-index all my directory, just new logs, so please don't answer "splunk clean eventdata -index _thefishbucket"
↧