<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304074#M57381</link>
    <description>&lt;P&gt;Yes, although this is a Dev environment so I don't mind if those are disrupted.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2018 15:52:27 GMT</pubDate>
    <dc:creator>andrewaalin</dc:creator>
    <dc:date>2018-02-22T15:52:27Z</dc:date>
    <item>
      <title>How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304071#M57378</link>
      <description>&lt;P&gt;crcSalt does not work with this type of input.&lt;BR /&gt;
If this were not binary data, I would do some text substitution with sed, but I don't know of a way to do that with binary evtx.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 22:20:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304071#M57378</guid>
      <dc:creator>andrewaalin</dc:creator>
      <dc:date>2018-02-21T22:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304072#M57379</link>
      <description>&lt;P&gt;Are you monitoring any other files from the forwarder where you want to collect WinEventLogs?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2018 22:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304072#M57379</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-02-21T22:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304073#M57380</link>
      <description>&lt;P&gt;WinEventLog is a modular input, it does not monitor files, but query the windows Winevent endpoint.&lt;BR /&gt;
Splunk uses a checkpoint to identify the latest event id collected per channel.&lt;/P&gt;

&lt;P&gt;If you want to reindex a channel, you can reset the checkpoint.&lt;BR /&gt;
1- stop splunk&lt;BR /&gt;
2 - Look on the forwarder in a folder like $SPLUNK_HOME\var\lib\splunk\modinputs\wineventlogs&lt;BR /&gt;
and in side the folder you will find a file (xml format) for each channel (security, applications etc..)&lt;BR /&gt;
3- remove the file&lt;BR /&gt;
4- restart splunk&lt;BR /&gt;
it should cause the forwarder to forget the last checkpoints, and restart from the beginning.&lt;BR /&gt;
warning : It may cause duplicates, as it will resend them all, and it may take some time to backfill all the events, if they are several month of old data.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 00:57:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304073#M57380</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2018-02-22T00:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304074#M57381</link>
      <description>&lt;P&gt;Yes, although this is a Dev environment so I don't mind if those are disrupted.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 15:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304074#M57381</guid>
      <dc:creator>andrewaalin</dc:creator>
      <dc:date>2018-02-22T15:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304075#M57382</link>
      <description>&lt;P&gt;Thanks, trying this out now.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 15:52:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304075#M57382</guid>
      <dc:creator>andrewaalin</dc:creator>
      <dc:date>2018-02-22T15:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304076#M57383</link>
      <description>&lt;P&gt;That worked, thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 17:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304076#M57383</guid>
      <dc:creator>andrewaalin</dc:creator>
      <dc:date>2018-02-22T17:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: How can I reindex a [WinEventLog://___] file with Splunk_TA_windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304077#M57384</link>
      <description>&lt;P&gt;&lt;IMG src="https://cdn.gamerant.com/wp-content/uploads/Vault-Boy-Thumbs-Up.jpg.optimal.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2018 17:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-reindex-a-WinEventLog-file-with-Splunk-TA-windows/m-p/304077#M57384</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2018-02-22T17:29:06Z</dc:date>
    </item>
  </channel>
</rss>

