Getting Data In

Is there a way to delete old log file in UF before start re-ingestion?


Hi, This is same scenario as my last question. I am getting data from a server where i have installed my UF. every night at 12 AM log file will generate with the date as mylog_yesterday_date.log. Sometimes i reboot the server, after rebooting the server, it's collecting all data from the shut down time.

Let's say I have shut down my server yesterday at 4:00 PM and rebooted today at 1:00 PM. After reboot the server it is collecting all data from shut down time (yesterday 4:00 PM) until reboot time (today 1:00 PM) and will continue gather data in real-time, this is happening in the server. When it's come to log creation, yesterday mid night log created as mylog_yesertday_date.log but the file has data until 4:00 PM because it has gathered until that time. This file is forwarding to Splunk. After rebooting server, it has full day data. Before i add this data to UF, currently i am deleting yesteday's half data and starting re-ingestion. Likewise I am getting data without data loss.

My question is, is there any way to delete the yesterday's half file data from UF automatically by comparing yesterday's log file last timestamp with the time 11:59 PM by writing scripts before start re-ingestion process? If so please let me know.


0 Karma


Does your inputs.conf have a setting crcSalt = <SOURCE>? Can you paste your inputs.conf

0 Karma


The UF keeps track of its position within the files it is monitoring and will resume where it left off following a reboot of the server or a restart of the UF. You shouldn't need to delete any data yourself.

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...