Getting Data In

Would the forwarder resend the previous data if all my indexer's eventdata is removed?

nickcode
Explorer

My deployment is:
1 Forwarder + 2 Indexers + 1 Search head.
I have specified a monitor in the forwarder and the forwarder has send all the data to the indexers. If remove all the eventdata in the indexers, then, what would the forwarder do next? Would it resend the previous data or just go on sending the new data to the indexers?

0 Karma
1 Solution

Ayn
Legend

It would only send new data to the indexers.

Forwarders keep track of what data they have or haven't read by writing metadata about their inputs in an internal index called the fishbucket. A forwarder has no idea about the status of the data on the indexer, it just knows the status of its inputs. You could reset this by cleaning out the fishbucket - this would result in that the forwarder would send all events it can find from the start in all its inputs.

View solution in original post

Ayn
Legend

It would only send new data to the indexers.

Forwarders keep track of what data they have or haven't read by writing metadata about their inputs in an internal index called the fishbucket. A forwarder has no idea about the status of the data on the indexer, it just knows the status of its inputs. You could reset this by cleaning out the fishbucket - this would result in that the forwarder would send all events it can find from the start in all its inputs.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...