Due to some inconsistencies in how some of our servers use Symbolic Links (symlinks), we need to understand how Splunk would handle the following situation...
/usr2/wlp_logs is a symlink pointing to /hosting/logs.
If we have the following 2 monitor stanzas in inputs.conf...
[monitor:///usr2/wlp_logs/blah/myapp.log]
[monitor:///hosting/logs/blah/myapp.log]
...would Splunk recognize that these are 2 references to the same file, and index it only once? Or, would myapp.log get indexed twice?
Thx for any clarification / enlightenment.
mfeeny1