Getting Data In

Why doesn't Splunk index old events in same log file?

SS1
Path Finder

Hi,

So i am trying to index the log file data.log, log file is 2 days old and splunk is indexing only the latest events. Is there a way i can index the older events in data.log ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
can you share your clients/UF's inputs.conf stanza for that file?
r. Ismo
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SS1,

if your system doesn't index logs older than 2 days, probably in your inputs.conf there's an "ignoreOlderThan" option.

So, if you want to index events older than two days you have to disable this option.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...