<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Set forwarder to Ignore previous logs in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204200#M21633</link>
    <description>&lt;P&gt;Hi Richgalloway, &lt;/P&gt;

&lt;P&gt;You can try adding the following setting in &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;: &lt;/P&gt;

&lt;P&gt;ignoreOlderThan = [s|m|h|d]&lt;BR /&gt;
* The monitor input will compare the modification time on files it encounters&lt;BR /&gt;
  with the current time.  If the time elapsed since the modification time&lt;BR /&gt;
  is greater than this setting, it will be placed on the ignore list.&lt;BR /&gt;
* Files placed on the ignore list will not be checked again for any&lt;BR /&gt;
  reason until the Splunk software restarts, or the file monitoring subsystem&lt;BR /&gt;
  is reconfigured.  This is true even if the file becomes newer again at a&lt;BR /&gt;
  later time.&lt;/P&gt;

&lt;P&gt;Hope it helps. Thanks!&lt;BR /&gt;
Hunter&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2016 14:43:26 GMT</pubDate>
    <dc:creator>hunters_splunk</dc:creator>
    <dc:date>2016-11-03T14:43:26Z</dc:date>
    <item>
      <title>Set forwarder to Ignore previous logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204199#M21632</link>
      <description>&lt;P&gt;We have the forwarder installed on a RHEL server to pull the kern messages into Splunk.  The requirement is Splunk should not pull the  logs when the server or Splunk service is down (meaning generally when a server is rebooted, splunk will go back to the history where it has stopped reading the logs and then pull the logs from there till recent), We don't want splunk to do that, so it should now pull logs only from the current time when the server or the splunk service has come up.  Is there a way we can do this?  There is no schedule for a reboot, it might be on adhoc basis.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 10:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204199#M21632</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2016-11-03T10:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Set forwarder to Ignore previous logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204200#M21633</link>
      <description>&lt;P&gt;Hi Richgalloway, &lt;/P&gt;

&lt;P&gt;You can try adding the following setting in &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;: &lt;/P&gt;

&lt;P&gt;ignoreOlderThan = [s|m|h|d]&lt;BR /&gt;
* The monitor input will compare the modification time on files it encounters&lt;BR /&gt;
  with the current time.  If the time elapsed since the modification time&lt;BR /&gt;
  is greater than this setting, it will be placed on the ignore list.&lt;BR /&gt;
* Files placed on the ignore list will not be checked again for any&lt;BR /&gt;
  reason until the Splunk software restarts, or the file monitoring subsystem&lt;BR /&gt;
  is reconfigured.  This is true even if the file becomes newer again at a&lt;BR /&gt;
  later time.&lt;/P&gt;

&lt;P&gt;Hope it helps. Thanks!&lt;BR /&gt;
Hunter&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 14:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204200#M21633</guid>
      <dc:creator>hunters_splunk</dc:creator>
      <dc:date>2016-11-03T14:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Set forwarder to Ignore previous logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204201#M21634</link>
      <description>&lt;P&gt;Right, you can set the &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; for few minutes. On a regular basis, you take a risk here that if the forwarder hasn't completed its job, you might lose data.&lt;/P&gt;

&lt;P&gt;Another way, it that upon reboot, you automatically adjust the &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; to 0 minutes. You can adjust your boot start script to take care of it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 14:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Set-forwarder-to-Ignore-previous-logs/m-p/204201#M21634</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-11-03T14:54:26Z</dc:date>
    </item>
  </channel>
</rss>

