Getting Data In

where was the checkpoints stored to allow splunk forwarder to skip events already sent earlier in case of reboot Splunk forwarder

msmita
New Member

Hi All,

Wanted to know ,is there any checkpoint stored to allow splunk forwarder to skip events already sent earlier after reboot the spunk forwarder.I am using version 7.1.4.

and if its not skipping earlier events ,Is there an alternative way of removing duplications?

Kindly do the needful.

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

When SplunkForwarder read file, it stores checkpoint(CRC) in fishbucket. Even after splunk service restart SplunkForwarder has all those checkpoint information in fishbucket.

Have a look at documentation https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Howlogfilerotationishandled so that you'll get idea how splunk reads rolling log files and how it calculates CRC.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

When SplunkForwarder read file, it stores checkpoint(CRC) in fishbucket. Even after splunk service restart SplunkForwarder has all those checkpoint information in fishbucket.

Have a look at documentation https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Howlogfilerotationishandled so that you'll get idea how splunk reads rolling log files and how it calculates CRC.

0 Karma

msmita
New Member

Thanks for the clarification.

One more query ,if same event is being transffered towards splunk enterprise but from different sourc ,will it check in fishbucket?

0 Karma

harsmarvania57
Ultra Champion

No, it will not check. CRC stored in fishbucket for every file you monitor using SplunkForwarder.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...