Knowledge Management

How do I get an existing index to freshly re-index the same data input directory

scodenton
Engager

Hi,

I accidentally truncated my index by dropping the index limit by 3 orders of magnitude. Instead of years of data, I now have a couple of days, but of course, Splunk won't re-index the existing old files that are still there in the data input directory.

Does anyone know how to simply trip Splunk into freshly re-indexing an index from scratch? Would it be as simple as deleting the data input directory entry and re-adding?

Do I need to delete the whole index and start again?

I don't want to delete the whole fishbucket, as there are many other indexes that are fine and that I would like to keep as-is.

I have 2,800 files to reindex, so not an option to manually add each one in via CLI.

Any thoughts most welcome,

Kind regards,

Scott

0 Karma
1 Solution

woodcock
Esteemed Legend

If these are files, you can write a script to call splunk add oneshot which ignores the fishbucket:

http://docs.splunk.com/Documentation/Splunk/6.4.1/Data/MonitorfilesanddirectoriesusingtheCLI

View solution in original post

woodcock
Esteemed Legend

If these are files, you can write a script to call splunk add oneshot which ignores the fishbucket:

http://docs.splunk.com/Documentation/Splunk/6.4.1/Data/MonitorfilesanddirectoriesusingtheCLI

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...