Getting Data In

Reset splunk forwarder to read a file from a particular offset

raknair07
Engager

Using btprobe with --reset causes the splunk forwarder to re-read the entire file. However i want the forwarder to read only from a particular offset, and not necessarily from the beginning of the file. Can i do that? Is there a way i can set the "sptr" attribute associated with each file, to a particular value.

dwaddle
SplunkTrust
SplunkTrust

I would say there is no supported way to do this using the btprobe command. The btprobe tool itself is only barely supported - falling into the category of "Command Line Tools for Use with Support." Further, the documentation on btprobe does not discuss any way of accomplishing anything other than a 'full reset'.

0 Karma

Lowell
Super Champion

I think the answer is no. Added an upvote because I'd like an authoritative answer to this as well.

MuS
Legend

nice one - up voted as well

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...