Getting Data In

How far back can be go when rebuilding the forwarders' assets?

ddrillic
Ultra Champion

Based on the interface of the DMC, it appears that we can go back only 24 hours when rebuilding the forwarder assets. I just did it in our production environment and only one forwarder is reported as missing. I'm pretty sure though that other forwarders are down for more than 24 hours. What can be done?

alt text

Tags (2)
0 Karma

Claw
Splunk Employee
Splunk Employee

Are you trying to collect the data from the missing forwarders or are you trying to add the forwarders to the Distributed Management Console.

This process deletes the sourcetype holding all of the existing forwarders and the process is usesually ONLY run oneself or so to clean up an environment where you have many forwarders missing and only want to see existing forwarders. Once you run this process, any forwarders that are no longer reporting are just gone and so is any data about them. This is not retrievable. The 24 hour question is asking how much back data for each forwarder do you want to collect. It cannot collect any data from forwarders that it no longer has any record of.

0 Karma

ddrillic
Ultra Champion

So, let's say a certain forwarder was down for 48 hours. Would it be included in the rebuilt list?

0 Karma

ddrillic
Ultra Champion

@Claw - any feedback on this one, by any chance?

0 Karma

ddrillic
Ultra Champion

Any thoughts about this one, by any chance?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...