I have already read this older thread on the subject -> : http://splunk-base.splunk.com/answers/5426/entire-file-contents-as-a-single-event
What i'd like to know is if there is a way to reindex the entire file upon change regardless of change type.
Using the method in the link above if you remove or add to the file anywhere inside it (apart from the end) the entire file will be indexed as a separate event (what I want). If I append a single entry to it only that event will show up.
My line breaks are fine (entire file is being indexed as a single event). Its only these additions that seem to break what I am trying to achieve.