Getting Data In

How to reset the forwarder to read all logs again and send them to the receiver?

cmlombardo
Path Finder

I need to reset the forwarder so it will read all my logs again and send them to the collector.
How can this be done?

Thank you.

Tags (1)
0 Karma

Ayn
Legend

On the forwarder machine, in Splunk's bin directory: splunk clean eventdata -index _fishbucket

http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning

Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...