Products/Services
product
- Why choose Splunk
- Installation record
- price
- Splunk Enterprise Security
- Splunk Phantom (SOAR)
- Splunk ITSI (Next Generation IT Operations)
- Splunk Observability Cloud
- Splunk UBA
- Macnica CSIRT App Basic
- App for Splunk for Financial Institutions
- Splunk Analytics for Hadoop
- About Apps
- Splunk Edge Hub
- What is Splunk
service
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
Specifications/Technical Information
Specifications/Technical Information
Evaluation machine application/FAQ
Application for evaluation machine
- FAQ
How to import only additional data
- release date
- 2016-09-21
- last updated
- 2024-01-11
- version
- Splunk Enterprise 9.0.4
- Overview
- If you want to only import additional data to prevent data volume from increasing, you can add followTail=1 to the [Monitor] stanza of inputs.conf to import only data that was imported after the setting was made.
- Reference information
- content
-
About data acquisition
Splunk will import all the data in the folders/files to be imported when data import settings are made. If the data to be imported is huge, it may take time to import the data or you may run out of licenses.
By making the following settings, it is possible to import data into Splunk from the data imported after the import settings have been made.
Setting method
- Open <SPLUNK_HOME>/etc/system/local/inputs.conf in a text editor.
- Add the following settings
[monitor://<取り込みたいファイルのパス>]
followTail = 1Example: When importing data under the /var/log folder using the above settings
[monitor:///var/log]
followTail = 1- restart splunk
that's all
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Weekdays: 9:00-17:00