All Apps and Add-ons

Does splunk upload old logs on server

sunnyparmar
Communicator

Hi,

I have a doubt about logs uploading data. Like I have installed Splunk forwarder on a server. In mid-night to avoid license violation if I stopped forwarder on the server and in next morning around 6 am once I will again restarted it so does forwarder send the logs for that time period as well during which it was stopped.

Thanks
Sunny

0 Karma
1 Solution

ddrillic
Ultra Champion

You can use ignoreOlderThan = 0d on the forwarder's inputs.conf. And right, it will index all applicable logs.

How to make a forwarder ignore logs other than today's -- ignoreOlderThan question

View solution in original post

woodcock
Esteemed Legend

Yes. It picks up wherever it left off with the pedal to the metal.

sunnyparmar
Communicator

thanks buddy..

0 Karma

ddrillic
Ultra Champion

You can use ignoreOlderThan = 0d on the forwarder's inputs.conf. And right, it will index all applicable logs.

How to make a forwarder ignore logs other than today's -- ignoreOlderThan question

View solution in original post

sunnyparmar
Communicator

Hi,

But in my default input.conf file the parameter you have mentioned is not included so what happened when next day i will start forwarder? Does it uploaded the logs of that time period during which it was stopped?

Thanks
Sunny

0 Karma

ddrillic
Ultra Champion

It should. It's all based on the timestamps of the log files and not on the period on which the forwarder was up or down.

0 Karma

sunnyparmar
Communicator

thanks a lot for your answer..

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!