Getting Data In

Would the forwarder resend the previous data if all my indexer's eventdata is removed?

nickcode
Explorer

My deployment is:
1 Forwarder + 2 Indexers + 1 Search head.
I have specified a monitor in the forwarder and the forwarder has send all the data to the indexers. If remove all the eventdata in the indexers, then, what would the forwarder do next? Would it resend the previous data or just go on sending the new data to the indexers?

0 Karma
1 Solution

Ayn
Legend

It would only send new data to the indexers.

Forwarders keep track of what data they have or haven't read by writing metadata about their inputs in an internal index called the fishbucket. A forwarder has no idea about the status of the data on the indexer, it just knows the status of its inputs. You could reset this by cleaning out the fishbucket - this would result in that the forwarder would send all events it can find from the start in all its inputs.

View solution in original post

Ayn
Legend

It would only send new data to the indexers.

Forwarders keep track of what data they have or haven't read by writing metadata about their inputs in an internal index called the fishbucket. A forwarder has no idea about the status of the data on the indexer, it just knows the status of its inputs. You could reset this by cleaning out the fishbucket - this would result in that the forwarder would send all events it can find from the start in all its inputs.

Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...