<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to reset heavy forwarder _fishbucket in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75980#M15516</link>
    <description>&lt;P&gt;try the hard method :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;stop splunk&lt;/LI&gt;
&lt;LI&gt;delete $SPLUNK_HOME/var/lib/splunk/fishbucket&lt;/LI&gt;
&lt;LI&gt;restart, and all will be re-detected as new.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Sat, 28 Sep 2013 01:14:01 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-09-28T01:14:01Z</dc:date>
    <item>
      <title>Need to reset heavy forwarder _fishbucket</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75979#M15515</link>
      <description>&lt;P&gt;We run SPLUNK in test and dev environment to test parsing logic before moved to production monitoring. so need to reset Heavy Forwarder to index from scratch once parsing logic has been updated.&lt;/P&gt;

&lt;P&gt;On the heavy forwarder i am trying to use&lt;/P&gt;

&lt;P&gt;$ ./splunk clean eventdata -index fishbucket This action will permanently erase all events from the index 'fishbucket'; it cannot be undone. Are you sure you want to continue [y/n]? y ERROR: Index 'fishbucket' does not exist. [ebstsf-17] /app/splunk/bin $ ./splunk clean eventdata _fishbucket This action will permanently erase all events from the index 'fishbucket'; it cannot be undone. Are you sure you want to continue [y/n]? y ERROR: Index '_fishbucket' does not exist. [ebstsf-17] /app/splunk/bin $ cd ../var/lib/&lt;/P&gt;

&lt;P&gt;Both commands throw ERROR: Index '_fishbucket' does not exist.&lt;/P&gt;

&lt;P&gt;please help&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:51:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75979#M15515</guid>
      <dc:creator>dgililo</dc:creator>
      <dc:date>2020-09-28T14:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need to reset heavy forwarder _fishbucket</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75980#M15516</link>
      <description>&lt;P&gt;try the hard method :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;stop splunk&lt;/LI&gt;
&lt;LI&gt;delete $SPLUNK_HOME/var/lib/splunk/fishbucket&lt;/LI&gt;
&lt;LI&gt;restart, and all will be re-detected as new.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 28 Sep 2013 01:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75980#M15516</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-09-28T01:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need to reset heavy forwarder _fishbucket</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75981#M15517</link>
      <description>&lt;P&gt;Just to throw another angle in here, are you doing index and forward? I've discovered (at least on v5.0.2) that if I clear an index, e.g. main, Splunk appears to either clear the fishbucket or the index has its own one associated with it...&lt;BR /&gt;
Might be me getting confused over the years but I didn't need to clear any fishbucket to restart indexing, as I'm certain I have in the past.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2013 23:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-to-reset-heavy-forwarder-fishbucket/m-p/75981#M15517</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-09-29T23:01:16Z</dc:date>
    </item>
  </channel>
</rss>

