<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I re-index an indexed S3 bucket? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185199#M18481</link>
    <description>&lt;P&gt;I've done all of the steps above and my generic S3 input is constantly stuck on &lt;CODE&gt;2017-11-18 05:56:44,694 level=INFO pid=71734 tid=Thread-4 logger=splunk_ta_aws.modinputs.generic_s3.aws_s3_data_loader pos=aws_s3_data_loader.py:_do_index_data:95 | datainput="irs_990" bucket_name="splunk4good-irs-form-990" | message="The last data ingestion iteration hasn't been completed yet."&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Nov 2017 05:59:27 GMT</pubDate>
    <dc:creator>skawasaki_splun</dc:creator>
    <dc:date>2017-11-18T05:59:27Z</dc:date>
    <item>
      <title>How do I re-index an indexed S3 bucket?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185196#M18478</link>
      <description>&lt;P&gt;Just helped Support with this and want to document the results...&lt;/P&gt;

&lt;P&gt;Let's say that I've indexed an S3 bucket, and realized that my line breakers were wrong and I need to reindex... well, I've got a seek pointer now that prevents me picking up the old data, so what do I do?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 01:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185196#M18478</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-01-16T01:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do I re-index an indexed S3 bucket?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185197#M18479</link>
      <description>&lt;P&gt;If you didn't delete the data from S3, you should be fine.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Delete the misindexed data. To soft-delete it, you can use the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delete" target="_blank"&gt;delete&lt;/A&gt; command, or to truly nuke it you can delete the index and make a new one.&lt;/LI&gt;
&lt;LI&gt;Fix your knowledge layer problem in &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf" target="_blank"&gt;props.conf&lt;/A&gt; -- by setting a sourcetype and turning off SHOULD_LINEMERGE, for instance.&lt;/LI&gt;
&lt;LI&gt;Delete the old modular input. It has cached a value for initial_scan_datetime that won't work for us, so we're going to configure a new input instead. &lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/AWS/ConfigureInputs#S3_inputs" target="_blank"&gt;http://docs.splunk.com/Documentation/AddOns/latest/AWS/ConfigureInputs#S3_inputs&lt;/A&gt; for background.&lt;/LI&gt;
&lt;LI&gt;Add a new modular input and set initial_scan_datetime to a long time ago. The add-on will now go get all of your data and Splunk will line break it properly.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185197#M18479</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2020-09-28T18:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: How do I re-index an indexed S3 bucket?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185198#M18480</link>
      <description>&lt;P&gt;Personally, I like using clean eventdata -index {{index}} . Saves a step.&lt;/P&gt;

&lt;P&gt;edit: this doesn't work on clustered indexes&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 02:14:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185198#M18480</guid>
      <dc:creator>dolivasoh</dc:creator>
      <dc:date>2015-01-16T02:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I re-index an indexed S3 bucket?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185199#M18481</link>
      <description>&lt;P&gt;I've done all of the steps above and my generic S3 input is constantly stuck on &lt;CODE&gt;2017-11-18 05:56:44,694 level=INFO pid=71734 tid=Thread-4 logger=splunk_ta_aws.modinputs.generic_s3.aws_s3_data_loader pos=aws_s3_data_loader.py:_do_index_data:95 | datainput="irs_990" bucket_name="splunk4good-irs-form-990" | message="The last data ingestion iteration hasn't been completed yet."&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2017 05:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-re-index-an-indexed-S3-bucket/m-p/185199#M18481</guid>
      <dc:creator>skawasaki_splun</dc:creator>
      <dc:date>2017-11-18T05:59:27Z</dc:date>
    </item>
  </channel>
</rss>

