I have a client server with a universal forwarder configured to forward data to an index server. On the client server, I have a folder "X" full of csv files. If I create a remote folder monitor for the client server folder "X" on my deployment server and deploy it to the client server. Will Splunk process the csv files that are already there. or will SPlunk not do anything until the folder contents changes?
↧