<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438961#M95834</link>
    <description>&lt;P&gt;Execute command below to reset fishbucket &lt;/P&gt;

&lt;P&gt;.\splunk.exe cmd btprobe -d "C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db" --file  &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:31:21 GMT</pubDate>
    <dc:creator>ssadanala1</dc:creator>
    <dc:date>2020-09-29T22:31:21Z</dc:date>
    <item>
      <title>deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438958#M95831</link>
      <description>&lt;P&gt;in Splunk Enterprise version 7.2.1,  Step 1. created a data input from "Files &amp;amp; Folders" | "New Local File &amp;amp; Directory" button.  For example:  D:\a4.   Then, ran a  search query from the D:\a4 contents and return results ok. &lt;BR /&gt;
Then, realized I mis-spelled "a4" so, deleted the data input "a4" from &lt;A href="http://localhost:8000/en-US/manager/search/data/inputs/monitor"&gt;http://localhost:8000/en-US/manager/search/data/inputs/monitor&lt;/A&gt;".  Next, in Windows Explorer, renamed  folder form "a4" to "b4" .&lt;BR /&gt;
And repeated Step1 and pointed to  D:\b4&lt;BR /&gt;
However, after running search  on the new data input directory, get no results.   Checked C:\Program Files\Splunk\etc\apps\search\local\inputs.conf . And "D:\a4" is not listed.  Please help me.  Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 22:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438958#M95831</guid>
      <dc:creator>qtorque95</dc:creator>
      <dc:date>2018-12-17T22:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438959#M95832</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/197958"&gt;@qtorque95&lt;/a&gt; : looks like you have Splunk-enterprise installed on your local...&lt;BR /&gt;
1.try running this command to check the inputs status of the monitor path &lt;BR /&gt;
   $SPLUNK_HOME/bin/splunk list input status&lt;BR /&gt;
2. if you see your monitor path from the list above, you can reset the file checkpoints(splunk might be thinking the  above file as a duplicate)&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.1/Troubleshooting/CommandlinetoolsforusewithSupport#btprobe" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.1/Troubleshooting/CommandlinetoolsforusewithSupport#btprobe&lt;/A&gt;&lt;BR /&gt;
    read this splunk doc on How Splunk calculates CRC..&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Howlogfilerotationishandled" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Howlogfilerotationishandled&lt;/A&gt;&lt;BR /&gt;
 3. Stop Splunk, delete fishbucket($SPLUNK_HOME/var/lib/splunk/fishbucket), and start splunk(this will reindex all files, NOT a best solution on prod boxes)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:30:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438959#M95832</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2020-09-29T22:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438960#M95833</link>
      <description>&lt;P&gt;thank you @prakash007 . 1. Using windows command prompt, typed, " cd C:\Program files\splunk\bin\ splunk.exe list input status ".  Another dos screen opens for 2 or 3 seconds, but not able to see the contents. Even tried to send results as follows: at C:\Program Files\Splunk\bin typed (shown in quotes), &lt;BR /&gt;
"splunk.exe list input status &amp;gt; inputstatus.txt " to see printed results. But got " Access Denied". I don't understand as I am  logged in as Administrator. &lt;BR /&gt;
3. Using Windows Control panel | Services, I stopped "Splunkd Service".  But not sure the syntax to run the "delete" fishbucket using windows command or Windows PowerShell. ( I searched for this, but  success). Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 22:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438960#M95833</guid>
      <dc:creator>qtorque95</dc:creator>
      <dc:date>2018-12-19T22:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438961#M95834</link>
      <description>&lt;P&gt;Execute command below to reset fishbucket &lt;/P&gt;

&lt;P&gt;.\splunk.exe cmd btprobe -d "C:\Program Files\SplunkUniversalForwarder\var\lib\splunk\fishbucket\splunk_private_db" --file  &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438961#M95834</guid>
      <dc:creator>ssadanala1</dc:creator>
      <dc:date>2020-09-29T22:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438962#M95835</link>
      <description>&lt;P&gt;Hello @qtorque95,&lt;/P&gt;

&lt;P&gt;Check out &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Howlogfilerotationishandled"&gt;How Splunk Enterprise handles log file rotation&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;When you or a log rotation program moves a file then Splunk recognizes that it is the same file and does not index it again.&lt;/P&gt;

&lt;P&gt;If you really want to index that file again, then I see two options:&lt;/P&gt;

&lt;P&gt;Option 1: Add the following line to your inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Doing so ensures that each file has a unique CRC.&lt;/P&gt;

&lt;P&gt;(You need to restart Splunk after making changes to configuration files.)&lt;/P&gt;

&lt;P&gt;Option 2: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk"&gt;You remove the indexed data&lt;/A&gt;. Do the following on the command line:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk clean eventdata -index &amp;lt;index_name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will delete the indexed data and reindex any inputs. You need to stop Splunk first before issuing this command.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 07:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438962#M95835</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2018-12-20T07:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: deleted data input file directory. Then, renamed and created a new data input directory. Ran Search but no results found</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438963#M95836</link>
      <description>&lt;P&gt;Thank you @whrg, @prakash007 for your answers. What i did to solve it: &lt;BR /&gt;
1.  in Windows server, went to Control Panel --&amp;gt; Services. &lt;BR /&gt;
2. Stop and start "Splunkd Service".&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 00:04:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/deleted-data-input-file-directory-Then-renamed-and-created-a-new/m-p/438963#M95836</guid>
      <dc:creator>qtorque95</dc:creator>
      <dc:date>2018-12-21T00:04:02Z</dc:date>
    </item>
  </channel>
</rss>

