<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change initial date then stop ingestion in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743391#M118103</link>
    <description>&lt;P&gt;I have disabled input (generic S3) of aws add-on for a year. After I enable it, it ingests old data so I disable it and change initial date in inputs.conf. After restarting splunk serevice, I enable it but no data coming. I tried clone and changed only the name. No data coming also. I don't know how to check it. Is it checkpoint issue or somethings? Please help me to check it.&lt;/P&gt;&lt;P&gt;Thanks for Advance&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2025 12:30:35 GMT</pubDate>
    <dc:creator>karn</dc:creator>
    <dc:date>2025-04-03T12:30:35Z</dc:date>
    <item>
      <title>Change initial date then stop ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743391#M118103</link>
      <description>&lt;P&gt;I have disabled input (generic S3) of aws add-on for a year. After I enable it, it ingests old data so I disable it and change initial date in inputs.conf. After restarting splunk serevice, I enable it but no data coming. I tried clone and changed only the name. No data coming also. I don't know how to check it. Is it checkpoint issue or somethings? Please help me to check it.&lt;/P&gt;&lt;P&gt;Thanks for Advance&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 12:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743391#M118103</guid>
      <dc:creator>karn</dc:creator>
      <dc:date>2025-04-03T12:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change initial date then stop ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743393#M118104</link>
      <description>&lt;P&gt;I change interval time to 600s also.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 12:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743393#M118104</guid>
      <dc:creator>karn</dc:creator>
      <dc:date>2025-04-03T12:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Change initial date then stop ingestion</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743396#M118105</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/123215"&gt;@karn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would have said clone the input, but you've done that? So the name of the input is definately different than the original? The reason I ask is that looking at the code, the checkpoint name is created based on the input name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The two checkpoint files that the Generic S3 Input creates (key/index ckpt) are stored in the checkpoint directory (typically&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;$SPLUNK_HOME/var/lib&lt;/SPAN&gt;&lt;SPAN&gt;/splunk/modinputs/aws&lt;/SPAN&gt;&lt;SPAN&gt;_s3) - Can you check in there to see what you have in there?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;You could stop Splunk and clear the relevant modinput checkpoint files and then start Splunk again.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;If that doesnt work then check you _internal logs for any errors, or more info about which data it is pulling in when the input runs.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 13:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-initial-date-then-stop-ingestion/m-p/743396#M118105</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-03T13:12:24Z</dc:date>
    </item>
  </channel>
</rss>

