<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277654#M69078</link>
    <description>&lt;P&gt;Yes you are correct. I apologize for the lack of clarity.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Sep 2016 16:26:34 GMT</pubDate>
    <dc:creator>brent_weaver</dc:creator>
    <dc:date>2016-09-14T16:26:34Z</dc:date>
    <item>
      <title>Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277652#M69076</link>
      <description>&lt;P&gt;I am having marginal success. We are writing out Linux VMs syslogs to table storage, which I can see with Azure Storage explorer but does not show up in Splunk after having added this table to storage account inputs. For storage account, do I put in the full URL or just the hostname?&lt;/P&gt;

&lt;P&gt;Does anyone have experience with this?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 15:47:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277652#M69076</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-14T15:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277653#M69077</link>
      <description>&lt;P&gt;Hi @brent_weaver - Just to clarify your question for other users, when you say "Azure Splunk App" are you referring to the Splunk Add-on for Microsoft Azure &lt;A href="https://splunkbase.splunk.com/app/3084/"&gt;https://splunkbase.splunk.com/app/3084/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 16:19:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277653#M69077</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-09-14T16:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277654#M69078</link>
      <description>&lt;P&gt;Yes you are correct. I apologize for the lack of clarity.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 16:26:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277654#M69078</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-14T16:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277655#M69079</link>
      <description>&lt;P&gt;No problem, thanks for clarifying. I just edited your post so we can try to get more visibility for you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 16:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277655#M69079</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-09-14T16:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277656#M69080</link>
      <description>&lt;P&gt;The world would be a better place if everyone was like the splunk community. THANK YOU!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 16:41:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277656#M69080</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-14T16:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277657#M69081</link>
      <description>&lt;P&gt;More information:&lt;/P&gt;

&lt;P&gt;Here is from the log file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-16-2016 14:11:56.653 +0000 DEBUG ExecProcessor - ExecProcessorSharedState::addToRunQueue() path='python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py' restartTimerIfNeeded=1
09-16-2016 14:11:56.653 +0000 DEBUG ExecProcessor - adding "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" to runqueue
09-16-2016 14:11:56.653 +0000 DEBUG ExecProcessor - cmd='python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py' Added to run queue
09-16-2016 14:11:56.653 +0000 DEBUG ExecProcessor - Running: python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py on PipelineSet 0
09-16-2016 14:11:56.653 +0000 DEBUG ExecProcessor - PipelineSet 0: Created new ExecedCommandPipe for "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py", uniqueId=1283
09-16-2016 14:11:56.738 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,737 DEBUG AzureStorageTable:237 - Starting AzureStorageTable.py 344
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,738 DEBUG AzureStorageTable:369 - XML: found configuration
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:374 - XML: found stanza AzureStorageTable://LinuxsyslogVer2v0
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'access_key'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'access_key' -&amp;gt; 'WYIl4RC07eU+XYiie/I8pdXFxBkcwxlPgNdVw8EEGF92Di808BCk2i/rBiaEG4ygbywJzEPSisSQsg1fg5dyUQ=='
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'dateTimeColumn'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'dateTimeColumn' -&amp;gt; 'TIMESTAMP'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'host'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'host' -&amp;gt; 'hdopeussadiag1a'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'index'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'index' -&amp;gt; 'bitbucket'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'interval'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'interval' -&amp;gt; '60'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'pollingMinutes'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'pollingMinutes' -&amp;gt; '3600'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'sourcetype'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'sourcetype' -&amp;gt; 'azure:storage:table'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:380 - XML: found param 'storage_account'
09-16-2016 14:11:56.739 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,739 DEBUG AzureStorageTable:384 - XML: 'storage_account' -&amp;gt; 'hdopeussadiag1a'
09-16-2016 14:11:56.740 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,740 DEBUG AzureStorageTable:380 - XML: found param 'table_name'
09-16-2016 14:11:56.740 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,740 DEBUG AzureStorageTable:384 - XML: 'table_name' -&amp;gt; 'LinuxsyslogVer2v0'
09-16-2016 14:11:56.740 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,740 DEBUG AzureStorageTable:264 - dateTimeStart = '2016-09-14T14:11:56.740547'
09-16-2016 14:11:56.740 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,740 DEBUG AzureStorageTable:271 - No dateTimeStart in inputs.conf...
09-16-2016 14:11:56.741 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,741 DEBUG AzureStorageTable:290 - Marker found for table LinuxsyslogVer2v0: 2028-06-17T20:31:07.379676+00:00
09-16-2016 14:11:56.741 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,741 DEBUG AzureStorageTable:299 - Filter string: TIMESTAMP gt datetime'2028-06-17T20:31:07.379676+00:00' and TIMESTAMP lt datetime'2028-06-20T08:31:07.379676+00:00'
09-16-2016 14:11:56.744 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,744 INFO connectionpool:657 - Starting new HTTPS connection (1): hdopeussadiag1a.table.core.windows.net
09-16-2016 14:11:59.633 +0000 DEBUG ExecProcessor - cmd='python /opt/splunk/etc/apps/splunk_app_db_connect/bin/rpcstart.py' Not added to run queue
09-16-2016 14:12:00.277 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:12:00,277 DEBUG connectionpool:350 - "GET /LinuxsyslogVer2v0()?$filter=TIMESTAMP%20gt%20datetime%272028-06-17T20%3A31%3A07.379676%2B00%3A00%27%20and%20TIMESTAMP%20lt%20datetime%272028-06-20T08%3A31%3A07.379676%2B00%3A00%27 HTTP/1.1" 200 None
09-16-2016 14:12:00.278 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:12:00,278 INFO AzureStorageTable:303 - Query returned 0 results.
09-16-2016 14:12:00.278 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:12:00,278 DEBUG AzureStorageTable:336 - No results found. Checkpoiting the end date/time used for query: 2028-06-20T08:31:07.379676+00:00
09-16-2016 14:12:00.278 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:12:00,278 DEBUG AzureStorageTable:343 - Ending AzureStorageTable.py 344
09-16-2016 14:12:00.290 +0000 DEBUG ExecProcessor - PipelineSet 0: Got EOF from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py", uniqueId=1283
09-16-2016 14:12:00.300 +0000 DEBUG ExecProcessor - PipelineSet 0: Ran script: python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py, took 3.647290 seconds to run, 0 bytes read
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It seems that the date ranges are wrong!?!?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 14:37:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277657#M69081</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-16T14:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277658#M69082</link>
      <description>&lt;P&gt;The issue seems to be that the date ranges are being picked as 2021-xx-xx?!?&lt;/P&gt;

&lt;P&gt;If I look at the log file I see this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-16-2016 14:11:56.741 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py" 2016-09-16 14:11:56,741 DEBUG AzureStorageTable:299 - Filter string: ***TIMESTAMP gt datetime'2028-06-17***T20:31:07.379676+00:00' and TIMESTAMP lt datetime'2028-06-20T08:31:07.379676+00:00'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Why is this happening? ENabled debug in the python script:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/TA-Azure/bin/AzureStorageTable.py&lt;/P&gt;

&lt;P&gt;Any advice is MUCH appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 16:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277658#M69082</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-19T16:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277659#M69083</link>
      <description>&lt;P&gt;The logic for the start date on the input works like this:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Set a start date to 2 days ago.  You'll see this in the debug message "AzureStorageTable:264 - dateTimeStart = '2016-09-14T14:11:56.740547'"&lt;/LI&gt;
&lt;LI&gt;Look for start date in inputs.conf.  If we find one, use it.  Otherwise use the 2 days ago one.  It looks like you don't have a start date specified, so you get the debug message "No dateTimeStart in inputs.conf..."&lt;/LI&gt;
&lt;LI&gt;Look for a marker from the check point directory (which holds the last date/time we saw when looping through table rows).  If there is a marker, then use the date/time from the marker.  Your data has a marker as evidenced by this message "DEBUG AzureStorageTable:290 - Marker found for table LinuxsyslogVer2v0: 2028-06-17T20:31:07.379676+00:00"&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;When looping through the table rows, we look at the field specified for the timestamp to see if it is greater than any other row (basically keeping a variable with the largest date/time seen in the data).  After looping through, we write this value to the checkpoint to use next time.  So, it looks like your data has an invalid time stamp in Azure (2028-06-17T20:31:07.379676+00:00).&lt;/P&gt;

&lt;P&gt;You can clear the checkpoint, but it will be beneficial to use the &lt;A href="http://storageexplorer.com/"&gt;Azure Storage Explorer&lt;/A&gt; to see where this errant data is logged.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 19:16:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277659#M69083</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2016-09-19T19:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277660#M69084</link>
      <description>&lt;P&gt;THANK YOU so much for the great information! &lt;/P&gt;

&lt;P&gt;I have already verified that the datetime in azure is correct.&lt;BR /&gt;
No date in inputs.conf&lt;/P&gt;

&lt;P&gt;Where is the checkpoint file? I cannot seem to find it even after having looked in the python script. Can this value be reset?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 20:10:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277660#M69084</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-19T20:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277661#M69085</link>
      <description>&lt;P&gt;I think this has been resolved by clearing the checkpoint file. I am doing more testing but it does seem to be getting logs. I will conclude this post with what I did to fix it if it does in fact work.&lt;/P&gt;

&lt;P&gt;THANK YOU!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 20:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277661#M69085</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-19T20:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: When configuring storage account inputs, do I write out the full URL or the hostname?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277662#M69086</link>
      <description>&lt;P&gt;I used this procedure to resolve this issue. It seems that somehow the input got checkpointed into 2021?!?!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Remove checkpoints
You can remove checkpoints by running the Splunk clean utility.

Caution: Be careful when removing checkpoints. Running the clean command removes your indexed data. For example, clean all removes ALL your indexed data.

For example, to remove checkpoints for a specific scheme:

splunk clean inputdata [&amp;lt;scheme&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So to resolve this I ran:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk clean inputdata AzureTableStorage
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This removed the check point file and splunk was in turn able to reset the checkpoint and carry on.&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 17:20:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-When-configuring-storage/m-p/277662#M69086</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2016-09-21T17:20:44Z</dc:date>
    </item>
  </channel>
</rss>

