Getting Data In

How to reset the forwarder to read all logs again and send them to the receiver?

cmlombardo
Path Finder

I need to reset the forwarder so it will read all my logs again and send them to the collector.
How can this be done?

Thank you.

Tags (1)
0 Karma

Ayn
Legend

On the forwarder machine, in Splunk's bin directory: splunk clean eventdata -index _fishbucket

http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...