<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No previous events when UF are installed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525360#M88709</link>
    <description>&lt;P&gt;If you reinstall the UF without uninstalling it then it will not re-index any data.&lt;/P&gt;&lt;P&gt;If you must delete the UF then be sure to preserve the fishbucket directory.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 13:32:48 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-10-19T13:32:48Z</dc:date>
    <item>
      <title>No previous events when UF are installed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525304#M88705</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;When UFs are installed, I don't want them to send all the events which were generated prior to UF was installed.&lt;/P&gt;&lt;P&gt;I just want UF to start sending logs when it was installed.&lt;/P&gt;&lt;P&gt;Is there a way to conf this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be honest we need to reinstall UFs for some reason and don't want the reinstalled UF to resend the previous events&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 08:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525304#M88705</guid>
      <dc:creator>jonwick</dc:creator>
      <dc:date>2020-10-19T08:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: No previous events when UF are installed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525360#M88709</link>
      <description>&lt;P&gt;If you reinstall the UF without uninstalling it then it will not re-index any data.&lt;/P&gt;&lt;P&gt;If you must delete the UF then be sure to preserve the fishbucket directory.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525360#M88709</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-19T13:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: No previous events when UF are installed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525364#M88710</link>
      <description>&lt;P&gt;Thanks for the reply &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I doubt of Windows server will allow reinstall by not uninstalling the existing one, (reinstalling will clear credentials and confs right?? That is what I want to be specific)&lt;/P&gt;&lt;P&gt;If we preserve fishbucket and paste it again to the newly installed server how reliable it would be ?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525364#M88710</guid>
      <dc:creator>jonwick</dc:creator>
      <dc:date>2020-10-19T13:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: No previous events when UF are installed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525396#M88714</link>
      <description>&lt;P&gt;Windows is quite happy to install new versions of Splunk UF without uninstalling the existing one.&amp;nbsp; I've not tried re-installing the same version.&lt;/P&gt;&lt;P&gt;To clear credentials, just remove the %SPLUNK_HOME%\etc\passwd file and restart the UF with a new user-seed file.&amp;nbsp; To clear configs, just delete the relevant .conf file(s) and restart the UF.&lt;/P&gt;&lt;P&gt;Preserving the fishbucket is very reliable.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 15:27:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-previous-events-when-UF-are-installed/m-p/525396#M88714</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-19T15:27:26Z</dc:date>
    </item>
  </channel>
</rss>

