Getting Data In

Is it possible to re-index lost AD logs?

dantimola
Communicator

Good Day fellow splunkers,

I just like to ask if is it still possible to re-index lost Windows Active Directory logs? Let's say, AD logs from a month a go. The reason why the logs lost is probably because of network issue. Please check my inputs.conf below.

[admon://default]
disabled = 0
monitorSubtree = 1
index = ad

Cheers,
Dan

0 Karma
1 Solution

DalJeanis
Legend

Okay, the answer depends on what you mean by "lost", and what you mean by "reindex".

If the log never got to splunk, but a copy is somewhere else that you can access, then YES. (search "manual load data")

If the log never got to splunk, and is not somewhere else that you can access, then NO.

If the log got to splunk, was indexed or went to the null queue, and the incoming log file was sent to oblivion and was not backed up, then NO. You got what you got.

If the log got to splunk, was indexed correctly or incorrectly, and the system is set up to move ingested files to a backup location, then YES. (Search for "reindex data")

If the log got to splunk, was indexed correctly, then got frozen and rolled off and you want it loaded back in, then YES. (Search for "reload frozen")

View solution in original post

0 Karma

DalJeanis
Legend

Okay, the answer depends on what you mean by "lost", and what you mean by "reindex".

If the log never got to splunk, but a copy is somewhere else that you can access, then YES. (search "manual load data")

If the log never got to splunk, and is not somewhere else that you can access, then NO.

If the log got to splunk, was indexed or went to the null queue, and the incoming log file was sent to oblivion and was not backed up, then NO. You got what you got.

If the log got to splunk, was indexed correctly or incorrectly, and the system is set up to move ingested files to a backup location, then YES. (Search for "reindex data")

If the log got to splunk, was indexed correctly, then got frozen and rolled off and you want it loaded back in, then YES. (Search for "reload frozen")

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...