<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to avoid forwarding the event which has already forwarded after restart of forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116188#M24258</link>
    <description>&lt;P&gt;Hi moohkhol,&lt;/P&gt;

&lt;P&gt;the default behavior of an universal forwarder is, to continue where it left ..... unless you did set &lt;CODE&gt;crcsalt = &amp;lt;SOURCE&amp;gt;&lt;/CODE&gt; for example. This can lead to re-indexing. &lt;/P&gt;

&lt;P&gt;You could use the &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; option in inputs.conf to ignore files that are older then your set value.&lt;/P&gt;

&lt;P&gt;Also, re-indexing will take place if the universal forwarders &lt;CODE&gt;fishbucket&lt;/CODE&gt; got cleaned by exectuing &lt;CODE&gt;splunk clean all&lt;/CODE&gt; or by removing files form &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk/fishbucket&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Wed, 02 Apr 2014 10:53:59 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-04-02T10:53:59Z</dc:date>
    <item>
      <title>How to avoid forwarding the event which has already forwarded after restart of forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116187#M24257</link>
      <description>&lt;P&gt;Today I have change configuration of forwarder and restarted it, after restart it is forwarding previous events as well which forwarder has already forwarder. &lt;/P&gt;

&lt;P&gt;How I can make sure that after restart, forwarder will only send latest data not previous one. &lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 10:15:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116187#M24257</guid>
      <dc:creator>moohkhol</dc:creator>
      <dc:date>2014-04-02T10:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to avoid forwarding the event which has already forwarded after restart of forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116188#M24258</link>
      <description>&lt;P&gt;Hi moohkhol,&lt;/P&gt;

&lt;P&gt;the default behavior of an universal forwarder is, to continue where it left ..... unless you did set &lt;CODE&gt;crcsalt = &amp;lt;SOURCE&amp;gt;&lt;/CODE&gt; for example. This can lead to re-indexing. &lt;/P&gt;

&lt;P&gt;You could use the &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; option in inputs.conf to ignore files that are older then your set value.&lt;/P&gt;

&lt;P&gt;Also, re-indexing will take place if the universal forwarders &lt;CODE&gt;fishbucket&lt;/CODE&gt; got cleaned by exectuing &lt;CODE&gt;splunk clean all&lt;/CODE&gt; or by removing files form &lt;CODE&gt;$SPLUNK_HOME/var/lib/splunk/fishbucket&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 10:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116188#M24258</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-04-02T10:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to avoid forwarding the event which has already forwarded after restart of forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116189#M24259</link>
      <description>&lt;P&gt;I have not set crcsalt in inputs.conf but still i am seeing that, forwarder is sending older data. I have controlled it with ignoreOlderThan =1d but this will still send duplicate data of 1 day. I am using heavy forwarder .. any though on this ??&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 11:41:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-forwarding-the-event-which-has-already-forwarded/m-p/116189#M24259</guid>
      <dc:creator>moohkhol</dc:creator>
      <dc:date>2014-04-02T11:41:49Z</dc:date>
    </item>
  </channel>
</rss>

