Getting Data In
Highlighted

Trouble re-creating sourcetype after delete

Communicator

I created some incorrect logs with the command

  • sourcetype="DS Logs" | delete

I have can_delete permission, and the process went through without any error. Then I changed input and transforms conf files and restarted Splunk to grab correct logs, but nothing happened. I can't clean the index because I need the data in that index that belong to other sourcetypes.

Please advise.

I cannot add new source or sourcetype and monitoring the DS sourcetype doesn't work anymore

Tags (1)
0 Karma
Highlighted
Highlighted

Re: Trouble re-creating sourcetype after delete

Communicator

This command solves my problem of re-adding the same logs

./splunk add oneshot /full/path/to/file -sourcetype mysourcetype -index myindex -host myhostparam

But I have new sourcetypes, and they are not going into Splunk either. What else do I have to do?

0 Karma
Highlighted

Re: Trouble re-creating sourcetype after delete

Communicator

Never mind. It's working now. The server TCP connection had an issue and that's why it's not updating the monitored logs.

0 Karma