When migrating Splunk Add-on for Amazon Web Services it turns out that it starts polling 6 months old data from stretch. I could not find any checkpoint setting in inputs.conf. Also via gui there is no such setting to set a begin date. Is there an option to set the begin date?
I've tried editing the aws_cloudwatch_logs_tasks.conf to set only_after but no luck.