<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder not pulling in past Window events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74940#M15313</link>
    <description>&lt;P&gt;I believe the "splunk clean all" would work for my issue, but the forwarder was installed remotely using psexec and I'm unable log into the console.  When I try to run "splunk clean all" through psexec it freezes and does not appear to do anything.  Do you know where onthe forwarder this information is stored?  Seems I could manually wipe the file instead.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2013 19:00:13 GMT</pubDate>
    <dc:creator>kmcconnell</dc:creator>
    <dc:date>2013-06-26T19:00:13Z</dc:date>
    <item>
      <title>Forwarder not pulling in past Window events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74938#M15311</link>
      <description>&lt;P&gt;I'm trying to pull in all the existing events from the Windows logs for a machine (application, security, &amp;amp; system).  I thought I had the inputs.conf setup correctly, but it is only pulling in events from the time that I pushed the inputs.conf file out (from the deployment server).  Below is the inputs.conf section:&lt;/P&gt;

&lt;P&gt;[WinEventLog:Application]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index=emn_investigation&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
evt_resolve_ad_obj = 1&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index=emn_investigation&lt;/P&gt;

&lt;P&gt;[WinEventLog:System]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
checkpointInterval = 5&lt;BR /&gt;
index=emn_investigation&lt;/P&gt;

&lt;P&gt;Am I missing a setting?  Do I need to remove the current_only = 0 setting?  This data is going into a new index so I can delete the data completely if I need to try something else.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74938#M15311</guid>
      <dc:creator>kmcconnell</dc:creator>
      <dc:date>2020-09-28T14:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not pulling in past Window events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74939#M15312</link>
      <description>&lt;P&gt;Did you by any chance configure this forwarders inputs multiple times so that it may have been monitoring and so it remembers the former position?&lt;/P&gt;

&lt;P&gt;You can clean out the forwarders memory of where it was in the event long by running the command "splunk clean all".&lt;/P&gt;

&lt;P&gt;Omid&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 20:52:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74939#M15312</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2013-06-25T20:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not pulling in past Window events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74940#M15313</link>
      <description>&lt;P&gt;I believe the "splunk clean all" would work for my issue, but the forwarder was installed remotely using psexec and I'm unable log into the console.  When I try to run "splunk clean all" through psexec it freezes and does not appear to do anything.  Do you know where onthe forwarder this information is stored?  Seems I could manually wipe the file instead.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 19:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74940#M15313</guid>
      <dc:creator>kmcconnell</dc:creator>
      <dc:date>2013-06-26T19:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not pulling in past Window events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74941#M15314</link>
      <description>&lt;P&gt;You could try deleting the files in the fishbucket directory located at $SPLUNK_home/var/lib/splunk/fishbucket&lt;/P&gt;

&lt;P&gt;Be sure the forwarder is stopped.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 20:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-pulling-in-past-Window-events/m-p/74941#M15314</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2013-06-26T20:53:22Z</dc:date>
    </item>
  </channel>
</rss>

