<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-send data with universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76266#M15564</link>
    <description>&lt;P&gt;There is currently no command that will clean &lt;EM&gt;only&lt;/EM&gt; the fishbucket (this is a bug, lack of foresight, something).  You should file an ER for this, but in the meantime you can just wipe the contents of $SPLUNK_DB/var/lib/splunk/fishbucket/ .&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2011 09:34:34 GMT</pubDate>
    <dc:creator>amrit</dc:creator>
    <dc:date>2011-04-07T09:34:34Z</dc:date>
    <item>
      <title>Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76265#M15563</link>
      <description>&lt;P&gt;When using a lightweight-forwarder we were able to clean the fishbucket (eventdata) so that we could re-forward data.  Trying this on the new universal forwarder yields the message "ERROR: Cleaning eventdata is not supported on this version."  Is there a new way to do this?&lt;/P&gt;

&lt;P&gt;Thanks,
Kevin&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2011 03:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76265#M15563</guid>
      <dc:creator>kevintelford</dc:creator>
      <dc:date>2011-04-07T03:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76266#M15564</link>
      <description>&lt;P&gt;There is currently no command that will clean &lt;EM&gt;only&lt;/EM&gt; the fishbucket (this is a bug, lack of foresight, something).  You should file an ER for this, but in the meantime you can just wipe the contents of $SPLUNK_DB/var/lib/splunk/fishbucket/ .&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2011 09:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76266#M15564</guid>
      <dc:creator>amrit</dc:creator>
      <dc:date>2011-04-07T09:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76267#M15565</link>
      <description>&lt;P&gt;Submitted: Case # 57213&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2011 22:51:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76267#M15565</guid>
      <dc:creator>kevintelford</dc:creator>
      <dc:date>2011-04-07T22:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76268#M15566</link>
      <description>&lt;P&gt;You want a cookie?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2011 00:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76268#M15566</guid>
      <dc:creator>amrit</dc:creator>
      <dc:date>2011-04-09T00:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76269#M15567</link>
      <description>&lt;P&gt;The &lt;CODE&gt;clean all&lt;/CODE&gt; command works for removing the fishbucket on a UF. Is there a reason you can't issue that command? &lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 18:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76269#M15567</guid>
      <dc:creator>cervelli</dc:creator>
      <dc:date>2011-07-20T18:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76270#M15568</link>
      <description>&lt;P&gt;I don't know his problem, but I guess this would wipe/reset the user/password data, wouldn't it?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2011 20:19:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76270#M15568</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-07-20T20:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76271#M15569</link>
      <description>&lt;P&gt;This did not work for me.  When UF was running, i got a error when I wiped out the content of 'fishbucket'.  I have to stop UF first, then remove all under 'fishbucket'. After restarting UF, i did not see any admon or Windows audit event resent.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2012 21:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76271#M15569</guid>
      <dc:creator>tonopahtaos</dc:creator>
      <dc:date>2012-08-02T21:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76272#M15570</link>
      <description>&lt;P&gt;Here is why:&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk clean eventdata&lt;BR /&gt;
This action will permanently erase all events from ALL indexes; it cannot be und&lt;BR /&gt;
one.&lt;BR /&gt;
Are you sure you want to continue [y/n]? y&lt;BR /&gt;
ERROR: Cleaning eventdata is not supported on this version.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2012 21:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76272#M15570</guid>
      <dc:creator>tonopahtaos</dc:creator>
      <dc:date>2012-08-02T21:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76273#M15571</link>
      <description>&lt;P&gt;cervelli said &lt;CODE&gt;clean all&lt;/CODE&gt;. not &lt;CODE&gt;clean eventdata&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2012 23:49:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76273#M15571</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-08-28T23:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76274#M15572</link>
      <description>&lt;P&gt;Four plus years and still no cookie.  Hopefully you don't treat all the ladies this way.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 18:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76274#M15572</guid>
      <dc:creator>kevin_telford</dc:creator>
      <dc:date>2015-07-15T18:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76275#M15573</link>
      <description>&lt;P&gt;clean all removed all user data, including admin. I cannot add admin back, because it requires authorization.&lt;BR /&gt;
catch 22&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 21:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76275#M15573</guid>
      <dc:creator>ferenc0521</dc:creator>
      <dc:date>2018-05-24T21:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Re-send data with universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76276#M15574</link>
      <description>&lt;P&gt;so tried clean all, but didn't see the files/events resent, moreover the admin user is gone, so &lt;BR /&gt;
 can't check with:&lt;BR /&gt;
&lt;A href="https://:8089/services/admin/inputstatus/TailingProcessor:FileStatus" target="test_blank"&gt;https://:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/A&gt;&lt;BR /&gt;
because no auth with admin is possible.&lt;/P&gt;

&lt;P&gt;I guess reinstall/config is next step&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 21:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Re-send-data-with-universal-forwarder/m-p/76276#M15574</guid>
      <dc:creator>ferenc0521</dc:creator>
      <dc:date>2018-05-24T21:50:52Z</dc:date>
    </item>
  </channel>
</rss>

