Deployment Architecture

How does Splunk forwarder handle data after uninstalling and reinstalling an app?

bruceclarke
Contributor

I have a bunch of forwarder machines that were inadvertently renamed recently. As a result, our forwarder manager no longer recognized the machines in the correct server class and apps were removed from the machine.

One of the apps that was removed forwards data from a file. Since the app was uninstalled and later reinstalled, will the forwarder resend data from that file? Or will it still remember which line was last forwarded and just pick up where it left off?

0 Karma
1 Solution

lguinn2
Legend

The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.

View solution in original post

lguinn2
Legend

The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...