<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index name is not getting changed in old log files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195035#M98649</link>
    <description>&lt;P&gt;What do you mean by "installing Splunk forwarder"?  Installing a forwarder does not enable any inputs other than the _* ones.  Do you really mean "adding an input" instead of "installing Splunk forwarder"?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jul 2015 19:52:07 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-07-07T19:52:07Z</dc:date>
    <item>
      <title>Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195028#M98642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have installed splunk universal forwarder on one of my windows server, while installing I've given the log directory details. I can see those logs in my index server by searching  host=&amp;lt;hostname&amp;gt;. Now I've created a new index (index=Test) and restarted splunk. I've updated the inputs.conf of the windows server where forwarder is installed and restarted my splunkForwarder service. Now if I search with index=Test host=&amp;lt;hostname&amp;gt;, I can see only the logs which came after updating the index in inputs.conf. The old logs which were in splunk already (before udpating the index), still doesn't in the new index. Please let me know how to make those old logs also within this index.&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 18:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195028#M98642</guid>
      <dc:creator>chris1</dc:creator>
      <dc:date>2015-07-07T18:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195029#M98643</link>
      <description>&lt;P&gt;You cannot; already-indexed data is immutable.  You can however &lt;CODE&gt;delete&lt;/CODE&gt; it and then trick your forwarders into sending it again.  That is your only option.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195029#M98643</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-07T19:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195030#M98644</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;Can you please give me more details about how to delete?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195030#M98644</guid>
      <dc:creator>chris1</dc:creator>
      <dc:date>2015-07-07T19:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195031#M98645</link>
      <description>&lt;P&gt;There is a &lt;CODE&gt;delete&lt;/CODE&gt; command (that doesn't really delete).  Read about it here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/delete"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/delete&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195031#M98645</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-07T19:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195032#M98646</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thank you so much..When I install the forwarder in windows server, I can select the directory, but there is no option to give the index for that. In this case how can I give the index while installing forwarder in windows?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:23:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195032#M98646</guid>
      <dc:creator>chris1</dc:creator>
      <dc:date>2015-07-07T19:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195033#M98647</link>
      <description>&lt;P&gt;Are you telling me that installing the Splunk Windows Universal Forwarder by default sends event to &lt;CODE&gt;index=Test&lt;/CODE&gt;?  I find this very hard to believe and have never seen this before.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195033#M98647</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-07T19:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195034#M98648</link>
      <description>&lt;P&gt;Hi Woodcock,&lt;/P&gt;

&lt;P&gt;Nope. I am just asking you.. is there any way to give the index details while installing splunk forwarder? I can see the option to select the directory, but I don't find any option related to index while installing forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195034#M98648</guid>
      <dc:creator>chris1</dc:creator>
      <dc:date>2015-07-07T19:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Index name is not getting changed in old log files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195035#M98649</link>
      <description>&lt;P&gt;What do you mean by "installing Splunk forwarder"?  Installing a forwarder does not enable any inputs other than the _* ones.  Do you really mean "adding an input" instead of "installing Splunk forwarder"?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-name-is-not-getting-changed-in-old-log-files/m-p/195035#M98649</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-07T19:52:07Z</dc:date>
    </item>
  </channel>
</rss>

