Today I have change configuration of forwarder and restarted it, after restart it is forwarding previous events as well which forwarder has already forwarder.
How I can make sure that after restart, forwarder will only send latest data not previous one.
Hi moohkhol,
the default behavior of an universal forwarder is, to continue where it left ..... unless you did set crcsalt = <SOURCE>
for example. This can lead to re-indexing.
You could use the ignoreOlderThan
option in inputs.conf to ignore files that are older then your set value.
Also, re-indexing will take place if the universal forwarders fishbucket
got cleaned by exectuing splunk clean all
or by removing files form $SPLUNK_HOME/var/lib/splunk/fishbucket
.
cheers, MuS
I have not set crcsalt in inputs.conf but still i am seeing that, forwarder is sending older data. I have controlled it with ignoreOlderThan =1d but this will still send duplicate data of 1 day. I am using heavy forwarder .. any though on this ??