All Apps and Add-ons

Do not update the data in the Splunk when updating CDR CMR files

AndreevAndrey
New Member

Shared database file CDR\CMR is very large. In Splyunk connected folder where the files you want copy data in CDR\CMR. But the data statistics of calls to Splunk are not updated. How to reset the Splunk? Suppose that the old data remains in the memory Splunk.

0 Karma

NOUMSSI
Builder

Hi,
I think that the data statistics of calls to Splunk are not updated because when you indexing the file option upload from file and directories and that is while when the file is updated on your disk, splunk doesn't take care of that changes.
To resolve this problem, you need to index that file with option continuously index data from file and directories

To reset splunk you can delete index and data that are containing in that index. To do it, run the CLI, go to the bin directory of spluk and run this commande:

if you're on Windows :

splunk clean eventdata -index <index_name>

where is the name of the targeted index

if you're on Windows :

./splunk clean eventdata -index <index_name>

After deleted them you can now reindexing them with option continuously index data from file and directories

AndreevAndrey
New Member

Hello.
Thank you for your comments.
1. It did not work to solve the problem. Did not find the setting of upload from file and directories\continuously index data from file and directories . Which window is installed?
2. Tried to install SPLUNK to start. Use instructions http://sideviewapps.com/apps/splunk-for-cisco-cdr/docs/configure-splunk-to-index-the-data/ Having trouble:
1. In the Splunk interface in your browser, go to the “Splunk for Cisco CDR” app - OK
2. From the app’s homepage click on “Manager”, and then “Data Inputs”. - No settings “Manager”, picture 1
3. From the app’s homepage click “Settings” in the top nav, then select “Data Inputs”. - Setting yes, picture 2
4. On the next screen, click the Big Green Button that says “Add Data” - Setting yes, picture 3
5. A large confusing page will load. The very first link on this page should be “a file or directory of files”. Click this link and no other. - no settings, see pictures
6. On the next screen, you will be given two options. Click “Consume any file on this Splunk server” - no settings, see pictures

No permission to insert a picture, I hope it will be clear and without pictures. I would be grateful for the help.
User may not apply to versions Splunk for Cisco CDR 3.4.6?

0 Karma

sideview
SplunkTrust
SplunkTrust

Yes, in short you don't want to index the CDR data with the "upload" option, but rather with the "continuously monitor" option. Or even better, In the app under "Setup" there is a page called "Setup data inputs" that will do all of it for you. If you follow the docs it will tell you to go back to the homepage when everything is ready, the homepage will tell you that it's time to go to the data input setup wizard, and the wizard will do the rest. I'm sorry you broke out of the docs and tried to figure it out yourself.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...