<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can not re-index file after delete in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170599#M34489</link>
    <description>&lt;P&gt;Hi tedfong,&lt;/P&gt;

&lt;P&gt;The delete command does not delete events, it just hides event from being shown in a search.  See the docs for more details &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Delete"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Delete&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To re-index your file you must first clean the fishbucket, this is where Splunk keeps track of the indexed files, see the docs for more detail &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Troubleshooting/CommandlinetoolsforusewithSupport#btprobe"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Troubleshooting/CommandlinetoolsforusewithSupport#btprobe&lt;/A&gt; to clean only one or more files. &lt;BR /&gt;
If you can remove everything that was indexed until now run this command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk clean all
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Cheers, MuS&lt;/P&gt;</description>
    <pubDate>Tue, 30 Dec 2014 07:26:42 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-12-30T07:26:42Z</dc:date>
    <item>
      <title>Can not re-index file after delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170598#M34488</link>
      <description>&lt;P&gt;I deleted all records by using the command&lt;BR /&gt;
 - sourcetype=cws_app_log|delete&lt;BR /&gt;
The records deleted successfully. &lt;BR /&gt;
However, i can not re-index another new file in the same directory/same sourcetype even i created a new sourcetype.&lt;BR /&gt;
Is there any problem? please help. thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170598#M34488</guid>
      <dc:creator>tedfong</dc:creator>
      <dc:date>2020-09-28T18:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can not re-index file after delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170599#M34489</link>
      <description>&lt;P&gt;Hi tedfong,&lt;/P&gt;

&lt;P&gt;The delete command does not delete events, it just hides event from being shown in a search.  See the docs for more details &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Delete"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Delete&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To re-index your file you must first clean the fishbucket, this is where Splunk keeps track of the indexed files, see the docs for more detail &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Troubleshooting/CommandlinetoolsforusewithSupport#btprobe"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Troubleshooting/CommandlinetoolsforusewithSupport#btprobe&lt;/A&gt; to clean only one or more files. &lt;BR /&gt;
If you can remove everything that was indexed until now run this command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk clean all
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 07:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170599#M34489</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-30T07:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can not re-index file after delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170600#M34490</link>
      <description>&lt;P&gt;I found the below error from the splunk log and try to fix it by by adding crcSalt as below. But seems its not work.&lt;/P&gt;

&lt;P&gt;12-30-2014 15:24:31.493 +0800 ERROR TailingProcessor - File will not be read, seekptr checksum did not match (file=E:\SPLUNK\CWS\INBOX\test\SIT\cws_a\csms_20141214_17_HKX35A.log).  Last time we saw this initcrc, filename was different.  You may wish to use a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;

&lt;P&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://E:\SPLUNK\CWS\INBOX\test\SIT\cws_a\*.log] 
disabled = false
followTail = 0
sourcetype = CWS_LOG_SIT3
index = main
crcSalt = 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170600#M34490</guid>
      <dc:creator>tedfong</dc:creator>
      <dc:date>2020-09-28T18:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can not re-index file after delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170601#M34491</link>
      <description>&lt;P&gt;If you want to use crcSalt it should look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 30 Dec 2014 07:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170601#M34491</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-30T07:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can not re-index file after delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170602#M34492</link>
      <description>&lt;P&gt;I got the error like below but it is not the last one. I am not able to index other file. It stopped at the last line&lt;/P&gt;

&lt;P&gt;12-30-2014 17:33:44.394 +0800 ERROR ApplicationUpdater - Error checking for update, URL=/api/apps:resolve/checkforupgrade: Connect to=&lt;A href="https://apps.splunk.com" target="_blank"&gt;https://apps.splunk.com&lt;/A&gt; timed out; exceeded 10sec&lt;BR /&gt;
12-30-2014 17:34:11.048 +0800 INFO  DatabaseDirectoryManager - Writing a bucket manifest in hotWarmPath='D:\Program Files\Splunk\var\lib\splunk_internaldb\db'.  Reason='Updating manifest: bucketUpdates=1'&lt;BR /&gt;
12-30-2014 17:34:11.095 +0800 INFO  DatabaseDirectoryManager - Writing a bucket manifest in hotWarmPath='D:\Program Files\Splunk\var\lib\splunk_introspection\db'.  Reason='Updating manifest: bucketUpdates=1'&lt;BR /&gt;
12-30-2014 17:34:12.048 +0800 INFO  DatabaseDirectoryManager - Writing a bucket manifest in hotWarmPath='D:\Program Files\Splunk\var\lib\splunk\audit\db'.  Reason='Updating manifest: bucketUpdates=1'&lt;BR /&gt;
12-30-2014 17:36:56.150 +0800 INFO  WatchedFile - Resetting fd to re-extract header.&lt;BR /&gt;
12-30-2014 17:36:56.150 +0800 INFO  BatchReader - Removed from queue file='E:\SPLUNK\CWS\INBOX\test\SIT\cws_app_log_sit2\20141215cws_app_log_sit1.csv'.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170602#M34492</guid>
      <dc:creator>tedfong</dc:creator>
      <dc:date>2020-09-28T18:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can not re-index file after delete</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170603#M34493</link>
      <description>&lt;P&gt;dear all,&lt;BR /&gt;
the problem solved after restarted splunk. thanks&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 10:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-re-index-file-after-delete/m-p/170603#M34493</guid>
      <dc:creator>tedfong</dc:creator>
      <dc:date>2014-12-30T10:13:32Z</dc:date>
    </item>
  </channel>
</rss>

