Getting Data In

Force Reload of Files

andrewkenth
Communicator

I am interested in reloading some files into Splunk however Splunk is (rightfully) ignoring the files as they havee already been loaded. Is there a way to force Splunk to reload these files?

Tags (1)
0 Karma
1 Solution

gfuente
Motivator

You need to clean the fishbucket (you can find how to do it here at splunk answers) or modify the header of the file, to make splunk think is a new one not indexed yet.

Regards

View solution in original post

0 Karma

gfuente
Motivator

You need to clean the fishbucket (you can find how to do it here at splunk answers) or modify the header of the file, to make splunk think is a new one not indexed yet.

Regards

0 Karma

andrewkenth
Communicator

I was able to do this by using the following commands:

splunk stop
splunk clean eventdata _fishbucket -index
splunk clean eventdata -index

Then I restart Splunk and moved the files I wanted to reload into monitored directories.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...