I noticed that our AD log inputs has a "start_from = oldest" entry. My question is, with this setting, if the forwarder is restarted, is it going to grab all the data, and probably give me duplicate data?
The short answer is "no". Even without that line, oldest
is the default setting so it would do that anyway. This just tells Splunk how to process a backlog: oldest->newest or newest->oldest. Read about it here: