<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to reindex the same source in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238077#M46246</link>
    <description>&lt;P&gt;I tried to reindex the following windows directories using "Monitor" from input data.&lt;/P&gt;

&lt;P&gt;d:\logs\appx&lt;BR /&gt;
d:\logs\appy&lt;BR /&gt;
d:\logs\trac&lt;/P&gt;

&lt;P&gt;the above folders contain 3-4 log files. &lt;BR /&gt;
I gave specific sourcetype for each data input folder. &lt;/P&gt;

&lt;P&gt;Splunk indexed "appx" and "trac" folders but not "appy" folder. I am unable to see the events from the search results for appy, but I can see Splunk showed count of appy directory under files &amp;amp; directories. I deleted the datainputs and sourcetype and added appy with different sourcetype and index but still I can't see the events in the search results.&lt;/P&gt;

&lt;P&gt;I tried to add crcsalt but I don't have permission to edit the input.conf file.&lt;/P&gt;

&lt;P&gt;How can I reindex the appy directory &lt;/P&gt;

&lt;P&gt;NOTE: Splunk indexing files under appy individually but not entire appy directory. &lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2016 20:32:49 GMT</pubDate>
    <dc:creator>vkakani60</dc:creator>
    <dc:date>2016-07-05T20:32:49Z</dc:date>
    <item>
      <title>How to reindex the same source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238077#M46246</link>
      <description>&lt;P&gt;I tried to reindex the following windows directories using "Monitor" from input data.&lt;/P&gt;

&lt;P&gt;d:\logs\appx&lt;BR /&gt;
d:\logs\appy&lt;BR /&gt;
d:\logs\trac&lt;/P&gt;

&lt;P&gt;the above folders contain 3-4 log files. &lt;BR /&gt;
I gave specific sourcetype for each data input folder. &lt;/P&gt;

&lt;P&gt;Splunk indexed "appx" and "trac" folders but not "appy" folder. I am unable to see the events from the search results for appy, but I can see Splunk showed count of appy directory under files &amp;amp; directories. I deleted the datainputs and sourcetype and added appy with different sourcetype and index but still I can't see the events in the search results.&lt;/P&gt;

&lt;P&gt;I tried to add crcsalt but I don't have permission to edit the input.conf file.&lt;/P&gt;

&lt;P&gt;How can I reindex the appy directory &lt;/P&gt;

&lt;P&gt;NOTE: Splunk indexing files under appy individually but not entire appy directory. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 20:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238077#M46246</guid>
      <dc:creator>vkakani60</dc:creator>
      <dc:date>2016-07-05T20:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to reindex the same source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238078#M46247</link>
      <description>&lt;P&gt;What timerange are you searching? Have you tried alltime?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 23:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238078#M46247</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-07-05T23:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to reindex the same source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238079#M46248</link>
      <description>&lt;P&gt;I am searching for "all time" only . Interesting thing is it is indexing individual files but not that directory. &lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 23:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238079#M46248</guid>
      <dc:creator>vkakani60</dc:creator>
      <dc:date>2016-07-05T23:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to reindex the same source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238080#M46249</link>
      <description>&lt;P&gt;Is it possible for you to run the following on the forwarder &lt;CODE&gt;./splunk cmd btool inputs list monitor&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 00:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238080#M46249</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-06T00:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to reindex the same source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238081#M46250</link>
      <description>&lt;P&gt;I am not fetching data from remote servers to run that forwarder command. &lt;/P&gt;

&lt;P&gt;Those directories are on splunk local server. (I mean that "appy" directory is located on D drive and splunk installed on C drive) no other servers connected using universal forwarder.. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 00:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238081#M46250</guid>
      <dc:creator>vkakani60</dc:creator>
      <dc:date>2016-07-06T00:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to reindex the same source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238082#M46251</link>
      <description>&lt;P&gt;I can index the individual file under that appy directory but not entire appy directory. Wondering why its not indexing because the logs in appy are similar to other folder logs but different application. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 00:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-the-same-source/m-p/238082#M46251</guid>
      <dc:creator>vkakani60</dc:creator>
      <dc:date>2016-07-06T00:55:30Z</dc:date>
    </item>
  </channel>
</rss>

