<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-ingest Windows logs across enterprise in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755380#M119852</link>
    <description>&lt;P&gt;It's not that easy.&lt;/P&gt;&lt;P&gt;Firstly, we have no idea what your configuration is (mostly inputs and outputs are of interest here)&lt;/P&gt;&lt;P&gt;Secondly, there is a very good question why didn't the forwarders stop and wait.&lt;/P&gt;&lt;P&gt;Thirdly, generally there is no native way to manipulate forwarder's internal state from remote. There are some ugly hacks to do it but I will not promote them here since it's very easy to shoot yourself in the foot that way.&lt;/P&gt;&lt;P&gt;Fourthly, with a normal desktop edition of windows 22 hours should not produce too many logs but on a busy server, depending on your configuration, that data could already have been overwritten if you hit the size limit.&lt;/P&gt;&lt;P&gt;Fifthly, if you do have the data on the other hand, removing checkpoints would mean rereading all available events from scratch so that could cause an overload of your license and/or infrastructure.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2025 16:33:41 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-11-10T16:33:41Z</dc:date>
    <item>
      <title>Re-ingest Windows logs across enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755339#M119843</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello, we had a multiday outage regarding the connectivity between the UFs and the IDXs.&amp;nbsp; This affected the ability of all the UFs (5k or so) from sending logs to Splunk from our Windows servers.&amp;nbsp; Once that connectivity was restored, for reasons yet to be determined, the UFs did not backfill, but kept sending current data.&amp;nbsp; What I'm saying is, the UFs for some reason did not realized that they could not send data and did not pause in their transmission.&amp;nbsp; Thus, we have about a 22 hour gap in our windows logs.&amp;nbsp; We are trying to figure out how to get Splunk to re-ingest that data.&amp;nbsp; All the searches I have found for re-ingestion of windows logs talk about deleting the checkpoint file for the time period and restarting Splunk.&amp;nbsp; That would work for one or a few servers, but we need to do that at scale.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems the options for re-ingestion past data at scale are limited to:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1. Use something like SCCM to script the stop of Splunk UF, deletion of checkpoint files, and restart Splunk UF&lt;/P&gt;&lt;P&gt;2. Use something like SCCM to completely uninstall Splunk UF and reinstall with a inputs.conf that covers the missing timeframe, but realize we will duplicate everything after that.&lt;/P&gt;&lt;P&gt;Is there another option?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I have found so far, but seems like it would only work for a few servers, not 5k&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Splunk-UF-not-onboarding-Previous-Winevent-Security-logs" target="_blank" rel="noopener"&gt;https://splunk.my.site.com/customer/s/article/Splunk-UF-not-onboarding-Previous-Winevent-Security-logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-do-I-trigger-the-re-indexing-of-events-from-a-locally/m-p/68917" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/How-do-I-trigger-the-re-indexing-of-events-from-a-locally/m-p/68917&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Nov 2025 20:03:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755339#M119843</guid>
      <dc:creator>reswob</dc:creator>
      <dc:date>2025-11-08T20:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Re-ingest Windows logs across enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755380#M119852</link>
      <description>&lt;P&gt;It's not that easy.&lt;/P&gt;&lt;P&gt;Firstly, we have no idea what your configuration is (mostly inputs and outputs are of interest here)&lt;/P&gt;&lt;P&gt;Secondly, there is a very good question why didn't the forwarders stop and wait.&lt;/P&gt;&lt;P&gt;Thirdly, generally there is no native way to manipulate forwarder's internal state from remote. There are some ugly hacks to do it but I will not promote them here since it's very easy to shoot yourself in the foot that way.&lt;/P&gt;&lt;P&gt;Fourthly, with a normal desktop edition of windows 22 hours should not produce too many logs but on a busy server, depending on your configuration, that data could already have been overwritten if you hit the size limit.&lt;/P&gt;&lt;P&gt;Fifthly, if you do have the data on the other hand, removing checkpoints would mean rereading all available events from scratch so that could cause an overload of your license and/or infrastructure.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 16:33:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755380#M119852</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-10T16:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Re-ingest Windows logs across enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755420#M119868</link>
      <description>&lt;P&gt;1. Good point. I should have been clearer in that I was hoping someone else had gone through this and could in general describe what they had done.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Noted.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Noted.&lt;/P&gt;&lt;P&gt;5. Noted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate the feedback.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 17:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-ingest-Windows-logs-across-enterprise/m-p/755420#M119868</guid>
      <dc:creator>reswob</dc:creator>
      <dc:date>2025-11-11T17:05:24Z</dc:date>
    </item>
  </channel>
</rss>

