<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: upload deleted iis log file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136322#M97843</link>
    <description>&lt;P&gt;i want to analyze the same log file what i have deleted&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2014 07:25:27 GMT</pubDate>
    <dc:creator>nkarthiece</dc:creator>
    <dc:date>2014-07-10T07:25:27Z</dc:date>
    <item>
      <title>upload deleted iis log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136321#M97842</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Yesterday i deleted one indexed iis logfile.&lt;/P&gt;

&lt;P&gt;But now i want to analyze the indexed iis log file.&lt;BR /&gt;
Please help me on this.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 06:30:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136321#M97842</guid>
      <dc:creator>nkarthiece</dc:creator>
      <dc:date>2014-07-10T06:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: upload deleted iis log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136322#M97843</link>
      <description>&lt;P&gt;i want to analyze the same log file what i have deleted&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 07:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136322#M97843</guid>
      <dc:creator>nkarthiece</dc:creator>
      <dc:date>2014-07-10T07:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: upload deleted iis log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136323#M97844</link>
      <description>&lt;P&gt;Have you deleted the file from the source machine or the events from the index or both?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 17:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136323#M97844</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-10T17:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: upload deleted iis log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136324#M97845</link>
      <description>&lt;P&gt;delete events from index...... using command&lt;BR /&gt;
source="D:\desktop\iislog server 8\14.8\W3SVC2\u_ex140711.log" aspx | delete&lt;/P&gt;

&lt;P&gt;Again i want to index the same file.its is not working&lt;BR /&gt;
please help me on this.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2014 06:42:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136324#M97845</guid>
      <dc:creator>nkarthiece</dc:creator>
      <dc:date>2014-07-11T06:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: upload deleted iis log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136325#M97846</link>
      <description>&lt;P&gt;Splunk remembers that it has already indexed that file in the fishbucket. You could either modify the file header, or provide a crcsalt in your inputs.conf. Emptying the fishbucket will affect other inputs on that machine. &lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2014 07:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/upload-deleted-iis-log-file/m-p/136325#M97846</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-11T07:28:51Z</dc:date>
    </item>
  </channel>
</rss>

