Getting Data In

How to undelete a input source

splukUP
Engager

I have a log file that was |delete'd from the index using search. I want the file back in the index. I did several steps of adding and removing the file as a Splunk input and restarting the machine's splunk. It just won't come back. Is there an easy way to |undelete?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

There is no way to undelete the data. If you still have the original data, you can reindex the file with the Splunk oneshot command, examples http://answers.splunk.com/questions/684/after-fixing-props-conf-how-to-re-index-the-same-files-using... and sort-of docs: http://www.splunk.com/base/Documentation/4.1.4/Admin/CLIadmincommands

Splunk normally remembers files it has already seen and won't reindex them (even if you rename them) but oneshot bypasses this mechanism.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

There is no way to undelete the data. If you still have the original data, you can reindex the file with the Splunk oneshot command, examples http://answers.splunk.com/questions/684/after-fixing-props-conf-how-to-re-index-the-same-files-using... and sort-of docs: http://www.splunk.com/base/Documentation/4.1.4/Admin/CLIadmincommands

Splunk normally remembers files it has already seen and won't reindex them (even if you rename them) but oneshot bypasses this mechanism.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...