All Apps and Add-ons

Maintain State of which logs ingested from blob

jralston
Explorer

We have a need to move our inputs for blob storage logs to a different forwarder. The problem is there is no way to define a time stamp to start ingestion from. So if we configure or re-configure the input it will start fresh and re-ingest ALL logs from that blob again. My question is how does the app maintain state to know what has been ingested and what has not?

0 Karma

jscraig2006
Communicator

i know this has been awhile. Did you ever find a solution? I has the same scenario.

0 Karma

jralston
Explorer

It has been a long time since I have looked at it but there are some meta-data files that maintain where it left off. If you look in app metadata folders you should be able to find it.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...