Getting Data In

Is it possible to re-index lost AD logs?

dantimola
Communicator

Good Day fellow splunkers,

I just like to ask if is it still possible to re-index lost Windows Active Directory logs? Let's say, AD logs from a month a go. The reason why the logs lost is probably because of network issue. Please check my inputs.conf below.

[admon://default]
disabled = 0
monitorSubtree = 1
index = ad

Cheers,
Dan

0 Karma
1 Solution

DalJeanis
Legend

Okay, the answer depends on what you mean by "lost", and what you mean by "reindex".

If the log never got to splunk, but a copy is somewhere else that you can access, then YES. (search "manual load data")

If the log never got to splunk, and is not somewhere else that you can access, then NO.

If the log got to splunk, was indexed or went to the null queue, and the incoming log file was sent to oblivion and was not backed up, then NO. You got what you got.

If the log got to splunk, was indexed correctly or incorrectly, and the system is set up to move ingested files to a backup location, then YES. (Search for "reindex data")

If the log got to splunk, was indexed correctly, then got frozen and rolled off and you want it loaded back in, then YES. (Search for "reload frozen")

View solution in original post

0 Karma

DalJeanis
Legend

Okay, the answer depends on what you mean by "lost", and what you mean by "reindex".

If the log never got to splunk, but a copy is somewhere else that you can access, then YES. (search "manual load data")

If the log never got to splunk, and is not somewhere else that you can access, then NO.

If the log got to splunk, was indexed or went to the null queue, and the incoming log file was sent to oblivion and was not backed up, then NO. You got what you got.

If the log got to splunk, was indexed correctly or incorrectly, and the system is set up to move ingested files to a backup location, then YES. (Search for "reindex data")

If the log got to splunk, was indexed correctly, then got frozen and rolled off and you want it loaded back in, then YES. (Search for "reload frozen")

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...