Getting Data In

How to reset the forwarder to read all logs again and send them to the receiver?

cmlombardo
Path Finder

I need to reset the forwarder so it will read all my logs again and send them to the collector.
How can this be done?

Thank you.

Tags (1)
0 Karma

Ayn
Legend

On the forwarder machine, in Splunk's bin directory: splunk clean eventdata -index _fishbucket

http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...