Hi,
So i am trying to index the log file data.log, log file is 2 days old and splunk is indexing only the latest events. Is there a way i can index the older events in data.log ?
Hi @SS1,
if your system doesn't index logs older than 2 days, probably in your inputs.conf there's an "ignoreOlderThan" option.
So, if you want to index events older than two days you have to disable this option.
Ciao.
Giuseppe