Getting Data In

Deleted historical data of source file. How to reindex the file

OMohi
Path Finder

I have deleted historical events from a source using the command | delete. Before doing this, I had added the stanza disabled=true from the deployment server on the target source input file, pushed the configuration to the forwarder server, and issued the | delete command to delete all the data from the targeted source input file. Finally, from the DS, I reconfigured the targeted forwarder input, by replacing disabled=true to disabled=false, and pushed the changes through Deployment Server, but I do not see anything coming from the forwarder's inputs file. There is no error on the splunk forwarder instance and the indexer instance on splunkd.log that would suggest any issues with the source input.

What am I doing wrong here? Is there a way to enable indexing on that inputs file . I created a separate monitoring stanza for that source input, before I was monitoring the folder where that file was situated. Now I am defining the exact file location, but to no avail.

Tags (2)
0 Karma

acharlieh
Influencer

The problem you're running into is that the fishbucket is telling the forwarder that it already sent the file, so the forwarder isn't trying to send the file. There is a very comprehensive answer of methods you can use for this here: http://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...