<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped. in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404443#M14580</link>
    <description>&lt;P&gt;If the log files are still there on the servers (with same name/location from where you were monitoring), those would get ingested automatically. If they've been rolled off to different location/name, you could create create a temporary monitoring input with same index/sourcetype and other setting but from different location to ingest those rolled logs. You can also use one shot method. See this for information on oneshot mehtod :&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorfilesanddirectoriesusingtheCLI"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorfilesanddirectoriesusingtheCLI&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2019 20:07:45 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2019-01-14T20:07:45Z</dc:date>
    <item>
      <title>Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404442#M14579</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;There is a splunkforwarder that was stopped for a week without our knowledge and the data from that server was not indexed. Is there a way to retrieve that missing 7 days of data into splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 18:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404442#M14579</guid>
      <dc:creator>pdantuuri0411</dc:creator>
      <dc:date>2019-01-14T18:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404443#M14580</link>
      <description>&lt;P&gt;If the log files are still there on the servers (with same name/location from where you were monitoring), those would get ingested automatically. If they've been rolled off to different location/name, you could create create a temporary monitoring input with same index/sourcetype and other setting but from different location to ingest those rolled logs. You can also use one shot method. See this for information on oneshot mehtod :&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorfilesanddirectoriesusingtheCLI"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Data/MonitorfilesanddirectoriesusingtheCLI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 20:07:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404443#M14580</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-01-14T20:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404444#M14581</link>
      <description>&lt;P&gt;Just restart the forwarder.  It will remember where it left off and forward in the missing logs.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 20:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404444#M14581</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-14T20:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404445#M14582</link>
      <description>&lt;P&gt;Hi @woodcock,&lt;/P&gt;

&lt;P&gt;That is what I thought was going to happen. Strangely it only retrieved the logs for the last few hours before it restarted(Restarted at 9 AM 01/14, only got logs from 12 AM 01/13)&lt;/P&gt;

&lt;P&gt;Is was reading about manually injecting these missing logs using splunk oneshot but the problem is we have one log file with logs from dates 01/05 - 01/14. If I use onshot, I am suspecting there will be multiple entries and will mess up the report that will be generated using this data. &lt;/P&gt;

&lt;P&gt;Please Advice&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 21:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404445#M14582</guid>
      <dc:creator>pdantuuri0411</dc:creator>
      <dc:date>2019-01-14T21:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404446#M14583</link>
      <description>&lt;P&gt;@somesoni2, &lt;/P&gt;

&lt;P&gt;Is was reading about manually injecting these missing logs using splunk oneshot but the problem is we have one log file with logs from dates 01/05 - 01/14. If I use onshot, I am suspecting there will be multiple entries and will mess up the report that will be generated using this data.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 21:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404446#M14583</guid>
      <dc:creator>pdantuuri0411</dc:creator>
      <dc:date>2019-01-14T21:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404447#M14584</link>
      <description>&lt;P&gt;just copy the log and trim it and then use oneshot on the modified file.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 21:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404447#M14584</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-14T21:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404448#M14585</link>
      <description>&lt;P&gt;The issue is there is no time stamp in the log file for the entries. I counted back hours to check on what date the entries started to log. Now if I use oneshot, how will splunk know the date of the entries? I assume this will not work. Please let me know if there is a work around?  Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 22:55:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404448#M14585</guid>
      <dc:creator>pdantuuri0411</dc:creator>
      <dc:date>2019-01-14T22:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404449#M14586</link>
      <description>&lt;P&gt;The issue is there is no time stamp in the log file for the entries. I counted back hours to check on what date the entries started to log. Now if I use oneshot, how will splunk know the date of the entries? I assume this will not work. Please let me know if there is a work around? Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 22:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404449#M14586</guid>
      <dc:creator>pdantuuri0411</dc:creator>
      <dc:date>2019-01-14T22:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404450#M14587</link>
      <description>&lt;P&gt;Copy the file.  Edit it.  Oneshot it.  Delete the copy.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 03:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404450#M14587</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-15T03:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404451#M14588</link>
      <description>&lt;P&gt;Are you using &lt;CODE&gt;DATETIME_CONFIG = CURRENT&lt;/CODE&gt;?  How is it timestamping them in the normal case?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 03:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404451#M14588</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-15T03:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404452#M14589</link>
      <description>&lt;P&gt;This is the configuration I have for this particular source type. This is from props.conf&lt;/P&gt;

&lt;P&gt;DATETIME_CONFIG =&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
category = Custom&lt;BR /&gt;
pulldown_type = true&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
disabled = false&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404452#M14589</guid>
      <dc:creator>pdantuuri0411</dc:creator>
      <dc:date>2020-09-29T22:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404453#M14590</link>
      <description>&lt;P&gt;So how is splunk setting &lt;CODE&gt;_time&lt;/CODE&gt; for your events in the normal case?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 22:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404453#M14590</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-15T22:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieved missing data that was not forwarded when the splunk forwarder is stopped.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404454#M14591</link>
      <description>&lt;P&gt;You should probably set a custom &lt;CODE&gt;datetime.xml&lt;/CODE&gt; to get the timestamp from the file/name.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 15:12:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Retrieved-missing-data-that-was-not-forwarded-when-the-splunk/m-p/404454#M14591</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-12-03T15:12:35Z</dc:date>
    </item>
  </channel>
</rss>

