<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: re-read a directory in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59274#M96868</link>
    <description>&lt;P&gt;you can add a &lt;CODE&gt;-sourcetype mysourcetype&lt;/CODE&gt; flag to the commmand line above.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2011 01:28:47 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2011-03-16T01:28:47Z</dc:date>
    <item>
      <title>re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59270#M96864</link>
      <description>&lt;P&gt;Having some trouble with a directory monitor:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[monitor:///usr/local/ecc_to_splunk/pickup/*.disk.*]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This monitor loaded the data, but I deleted it (for unrelated reasons) and am having trouble getting splunk to read it again.  After deleting the data in splunk using &lt;CODE&gt;|delete&lt;/CODE&gt;, I removed the files from the dir, disabled then enabled the monitor, then put the same files back.  &lt;/P&gt;

&lt;P&gt;It seems as though splunk isn't reading the files because it already has once.  Is there a way to override this and force splunk to read them?  Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 13:14:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59270#M96864</guid>
      <dc:creator>dinisco</dc:creator>
      <dc:date>2011-03-15T13:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59271#M96865</link>
      <description>&lt;P&gt;If I understand you correctly, Splunk has previously indexed the data.  Even if you delete the source file(s) and then later on re-add them, I do not think Splunk will re-index them as they already existing within Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 20:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59271#M96865</guid>
      <dc:creator>netwrkr</dc:creator>
      <dc:date>2011-03-15T20:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59272#M96866</link>
      <description>&lt;P&gt;You can force Splunk to forget &lt;EM&gt;all&lt;/EM&gt; file history that it has read by cleaning out the fishbucket directory (while Splunk is down) on the machine where it was read from. This probably isn't what you want. You can also have Splunk re-index a specific file using:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk add oneshot /usr/local/ecc_to_splunk/pickup/file1.disk.ext
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can't wildcard this, you have to run this for each specific file name, though you could of course script that in the shell.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 21:20:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59272#M96866</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-03-15T21:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59273#M96867</link>
      <description>&lt;P&gt;Thanks this is exactly what I was looking for.  Is there a way to set the sourcetype?  I have one specifically defined for these files in tranforms.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 23:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59273#M96867</guid>
      <dc:creator>dinisco</dc:creator>
      <dc:date>2011-03-15T23:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59274#M96868</link>
      <description>&lt;P&gt;you can add a &lt;CODE&gt;-sourcetype mysourcetype&lt;/CODE&gt; flag to the commmand line above.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2011 01:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59274#M96868</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-03-16T01:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59275#M96869</link>
      <description>&lt;P&gt;So I had the same problem, I had &lt;CODE&gt;| delete&lt;/CODE&gt;-ed a bunch of data, but then wanted to re-add to splunk. &lt;/P&gt;

&lt;P&gt;When using &lt;CODE&gt;./splunk add oneshot&lt;/CODE&gt; all the data was added back to splunk BUT the timestamp for ALL the data was from when it was re-added, not the original modtime of the file (input is a directory with 2000+ log files). is there a way to have it re-index using the timestamp of the files?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 12:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59275#M96869</guid>
      <dc:creator>joshrabinowitz</dc:creator>
      <dc:date>2011-06-15T12:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: re-read a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59276#M96870</link>
      <description>&lt;P&gt;well I'm dumb, and should read things first, like putting new data into a test index to make sure it looks ok and test props.conf etc. i guess i can just make a new index and splunk should index with correct timestamps&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 12:57:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/re-read-a-directory/m-p/59276#M96870</guid>
      <dc:creator>joshrabinowitz</dc:creator>
      <dc:date>2011-06-15T12:57:35Z</dc:date>
    </item>
  </channel>
</rss>

