I know that by deleting the fishbucket index Splunk will re-index everything. Is there a way to selectively re-index data for a particular source or sourcetype?
Thx.
Craig
Yes, you can use btprobe
command in the forwarder (or wherever the data source is located) to reset the (fishbucket) entry for a given key or particular file in fishbucket's btree.
There is more info here: http://docs.splunk.com/Documentation/Splunk/4.3.2/Troubleshooting/CommandlinetoolsforusewithSupport#...
Hope it helps.
Yes, you can use btprobe
command in the forwarder (or wherever the data source is located) to reset the (fishbucket) entry for a given key or particular file in fishbucket's btree.
There is more info here: http://docs.splunk.com/Documentation/Splunk/4.3.2/Troubleshooting/CommandlinetoolsforusewithSupport#...
Hope it helps.
How do I figure out what the key is for a particular sourcetype or source?