Deployment Architecture

How does Splunk forwarder handle data after uninstalling and reinstalling an app?

bruceclarke
Contributor

I have a bunch of forwarder machines that were inadvertently renamed recently. As a result, our forwarder manager no longer recognized the machines in the correct server class and apps were removed from the machine.

One of the apps that was removed forwards data from a file. Since the app was uninstalled and later reinstalled, will the forwarder resend data from that file? Or will it still remember which line was last forwarded and just pick up where it left off?

0 Karma
1 Solution

lguinn2
Legend

The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.

View solution in original post

lguinn2
Legend

The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.

Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...