<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: re-index windows event logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138986#M28573</link>
    <description>&lt;P&gt;Hi bjoernjensen,&lt;/P&gt;

&lt;P&gt;there is another option for &lt;CODE&gt;crcSalt&lt;/CODE&gt; which is very useful - &lt;EM&gt;funny this is not in the docs?!?&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;you can use the &lt;CODE&gt;crcSalt = REINDEXMEPLEASE&lt;/CODE&gt; option in any &lt;CODE&gt;inputs.conf&lt;/CODE&gt; stanza to get this input re-indexed. &lt;BR /&gt;
Add it to the stanz, restart the forwarder and let it do the work. After that, don't forget to remove the entry again .... &lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 09 Feb 2015 14:40:12 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2015-02-09T14:40:12Z</dc:date>
    <item>
      <title>re-index windows event logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138985#M28572</link>
      <description>&lt;P&gt;I would like to force the re-indexing of events in a local Windows Event Log channel, let's say "Security". I have tried to use crcSalt (inputs.conf) but it had no effect on the Windows Event Log events. How can I do this?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 14:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138985#M28572</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2015-02-09T14:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: re-index windows event logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138986#M28573</link>
      <description>&lt;P&gt;Hi bjoernjensen,&lt;/P&gt;

&lt;P&gt;there is another option for &lt;CODE&gt;crcSalt&lt;/CODE&gt; which is very useful - &lt;EM&gt;funny this is not in the docs?!?&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;you can use the &lt;CODE&gt;crcSalt = REINDEXMEPLEASE&lt;/CODE&gt; option in any &lt;CODE&gt;inputs.conf&lt;/CODE&gt; stanza to get this input re-indexed. &lt;BR /&gt;
Add it to the stanz, restart the forwarder and let it do the work. After that, don't forget to remove the entry again .... &lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 14:40:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138986#M28573</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-09T14:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: re-index windows event logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138987#M28574</link>
      <description>&lt;P&gt;Hi MuS,&lt;/P&gt;

&lt;P&gt;I just tested it without success.&lt;/P&gt;

&lt;P&gt;Remember that crcSalt is being added to the hash of the first x bytes of a file being monitored to decide . Where x is equal to initCrcLength (inputs.conf default is 256). &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/admin/Inputsconf"&gt;inputs.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am running Splunk 6.2.0. Furthermore I am indexing on the Splunk machine (local Windows Event Logs).&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 15:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138987#M28574</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2015-02-09T15:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: re-index windows event logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138988#M28575</link>
      <description>&lt;P&gt;the &lt;CODE&gt;REINDEXMEPLEASE&lt;/CODE&gt; worked so far for me, never had troubles. Take a look at this post about cleaning the &lt;CODE&gt;_fishbucket&lt;/CODE&gt; &lt;A href="http://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html"&gt;http://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html&lt;/A&gt; this applies to an indexer and an universal forwarder.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 15:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138988#M28575</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-09T15:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: re-index windows event logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138989#M28576</link>
      <description>&lt;P&gt;This could work once for a file I want to re-index. But I am looking on Windows Event Logs here. AFAIK handeling for this kind of pointer is done differently. From 2011 I found this post: &lt;A href="http://answers.splunk.com/answers/30006/how-do-i-trigger-the-re-indexing-of-events-from-a-locally-collected-windows-event-log-channel.html"&gt;Link&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Unfortunately these checkpoint files do not exist on my system / any more.&lt;/P&gt;

&lt;P&gt;All the best - Bjoern&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2015 15:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-index-windows-event-logs/m-p/138989#M28576</guid>
      <dc:creator>bjoernjensen</dc:creator>
      <dc:date>2015-02-09T15:45:51Z</dc:date>
    </item>
  </channel>
</rss>

