Getting Data In

Trouble re-creating sourcetype after delete

lain179
Communicator

I created some incorrect logs with the command

  • sourcetype="DS Logs" | delete

I have can_delete permission, and the process went through without any error. Then I changed input and transforms conf files and restarted Splunk to grab correct logs, but nothing happened. I can't clean the index because I need the data in that index that belong to other sourcetypes.

Please advise.

I cannot add new source or sourcetype and monitoring the DS sourcetype doesn't work anymore

Tags (1)
0 Karma
1 Solution

lain179
Communicator

Never mind. It's working now. The server TCP connection had an issue and that's why it's not updating the monitored logs.

0 Karma

lain179
Communicator

This command solves my problem of re-adding the same logs

./splunk add oneshot /full/path/to/file -sourcetype mysourcetype -index myindex -host myhostparam

But I have new sourcetypes, and they are not going into Splunk either. What else do I have to do?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...