Getting Data In

Is it possible to re-index file data for a specific source or sourcetype in Splunk?

rameshlpatel
Communicator

Hi,

I have requirement where i wants to re-index file data for specific sourcetype or source ?

Is it possible to do in splunk ?

strive
Influencer

For cleaning and re-indexing refer this link

http://answers.splunk.com/answers/1203/why-wont-splunk-re-index-my-data

In this link Yann has given 3 nice options to re-index a file. Just like my earlier comment renaming is one of the options

http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning

strive
Influencer

You want to clean the data and re-index or you just want to re-index?

0 Karma

somesoni2
Revered Legend

Or you can use Splunk CLI oneshot to add the data again.

See this
http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/MonitorfilesanddirectoriesusingtheCLI

strive
Influencer

Yes it is possible. Change the filename and try. If filename is your source then change file modification time and try.

0 Karma
Get Updates on the Splunk Community!

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...