<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When indexing historic and real time data together, does Splunk index old data first and new data last or vice versa? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207282#M40887</link>
    <description>&lt;P&gt;When indexing a file, it indexes line by line, starting with the beginning, and ending with the end of file.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2016 20:05:35 GMT</pubDate>
    <dc:creator>bshuler_splunk</dc:creator>
    <dc:date>2016-11-02T20:05:35Z</dc:date>
    <item>
      <title>When indexing historic and real time data together, does Splunk index old data first and new data last or vice versa?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207281#M40886</link>
      <description>&lt;P&gt;I have to index the historic data along with real time data from the log file. May I know from which point the indexing starts; whether it starts ingesting old data first and latest data at the end, or vice versa? . &lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 16:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207281#M40886</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2016-11-02T16:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: When indexing historic and real time data together, does Splunk index old data first and new data last or vice versa?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207282#M40887</link>
      <description>&lt;P&gt;When indexing a file, it indexes line by line, starting with the beginning, and ending with the end of file.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 20:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207282#M40887</guid>
      <dc:creator>bshuler_splunk</dc:creator>
      <dc:date>2016-11-02T20:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: When indexing historic and real time data together, does Splunk index old data first and new data last or vice versa?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207283#M40888</link>
      <description>&lt;P&gt;thank you, Suppose the UF is restarted ,May I know how Splunk remember the line where it got stopped previously to start ingestion from that point. If not will it start ingestion again from the beggining of the file?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 20:37:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207283#M40888</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2016-11-02T20:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: When indexing historic and real time data together, does Splunk index old data first and new data last or vice versa?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207284#M40889</link>
      <description>&lt;P&gt;There is a "magic" index called fishbucket. All of the pointers for remembering the last location for files are in it. Splunk does not forget and reindex.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 01:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-indexing-historic-and-real-time-data-together-does-Splunk/m-p/207284#M40889</guid>
      <dc:creator>bshuler_splunk</dc:creator>
      <dc:date>2016-11-03T01:22:26Z</dc:date>
    </item>
  </channel>
</rss>

