the default behavior of an universal forwarder is, to continue where it left ..... unless you did set
crcsalt = <SOURCE> for example. This can lead to re-indexing.
You could use the
ignoreOlderThan option in inputs.conf to ignore files that are older then your set value.
Also, re-indexing will take place if the universal forwarders
fishbucket got cleaned by exectuing
splunk clean all or by removing files form
I have not set crcsalt in inputs.conf but still i am seeing that, forwarder is sending older data. I have controlled it with ignoreOlderThan =1d but this will still send duplicate data of 1 day. I am using heavy forwarder .. any though on this ??