All Apps and Add-ons

Maintain State of which logs ingested from blob

jralston
Explorer

We have a need to move our inputs for blob storage logs to a different forwarder. The problem is there is no way to define a time stamp to start ingestion from. So if we configure or re-configure the input it will start fresh and re-ingest ALL logs from that blob again. My question is how does the app maintain state to know what has been ingested and what has not?

0 Karma

jscraig2006
Communicator

i know this has been awhile. Did you ever find a solution? I has the same scenario.

0 Karma

jralston
Explorer

It has been a long time since I have looked at it but there are some meta-data files that maintain where it left off. If you look in app metadata folders you should be able to find it.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...