Getting Data In

How to reset the forwarder to read all logs again and send them to the receiver?

cmlombardo
Path Finder

I need to reset the forwarder so it will read all my logs again and send them to the collector.
How can this be done?

Thank you.

Tags (1)
0 Karma

Ayn
Legend

On the forwarder machine, in Splunk's bin directory: splunk clean eventdata -index _fishbucket

http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...