Hi,
I am new to splunk and when i add datainputs i was not known about the timestamp issue and later i explored it. when i am trying to delete a data input and trying to reinsert it with proper format, i found that the earlier input is still indexed and when i am querying it , i am able to find it. i tried restarting splunk through splunk manager as well as windows services.(both splunkd and splunkweb)
Hi,
Welcome to the world of Splunk...
Without re-writing what has already been written... the following documentation would be helpful here.
http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk
Hi,
Welcome to the world of Splunk...
Without re-writing what has already been written... the following documentation would be helpful here.
http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk