Worked through the tutorial on splunkstorm and when done wanted to delete the data via the storage web UI and accidentally deleted a log file that a forwarder was monitoring. File still shows as being monitored on the server but not see the data. Is there some kind of reset or re-index that needs to be done?
thanks
Normally if you remove the content in splunkforwarder/var/lib/splunk/fishbucket
it should restart monitoring as new and resend everything