How to import only additional data

release date
2016-09-21
last updated
2016-09-21
version
Splunk Enterprise 6.4.3
Overview
How to import only additional data
Reference information
content

About data acquisition

Splunk will import all the data in the folders/files to be imported when data import settings are made. If the data to be imported is huge, it may take time to import the data or you may run out of licenses.

By making the following settings, it is possible to import data into Splunk from the data imported after the import settings have been made.

Setting method

  • Open <SPLUNK_HOME>/etc/system/local/inputs.conf in a text editor.
  • Add the following settings
[monitor://<取り込みたいファイルのパス>]
followTail = 1

Example: When importing data under the /var/log folder using the above settings

[monitor:///var/log]
followTail = 1
  • restart splunk

that's all