I created some incorrect logs with the command
I have can_delete permission, and the process went through without any error. Then I changed input and transforms conf files and restarted Splunk to grab correct logs, but nothing happened. I can't clean the index because I need the data in that index that belong to other sourcetypes.
I cannot add new source or sourcetype and monitoring the DS sourcetype doesn't work anymore
This command solves my problem of re-adding the same logs
./splunk add oneshot /full/path/to/file -sourcetype mysourcetype -index myindex -host myhostparam
But I have new sourcetypes, and they are not going into Splunk either. What else do I have to do?
Never mind. It's working now. The server TCP connection had an issue and that's why it's not updating the monitored logs.