Monitoring Splunk

How can I re-index license-usage.log?

tkwaller_2
Communicator

Hello

Someone prior to me had set the license master to forward logs to the wrong hosts so when I fixed it I have no historical data for license usage.
Whats the best way to fix this?

Thanks for the assistance!

0 Karma
1 Solution

CarsonZa
Contributor

one of the following is what i use

  • modify the first line of the files to reindex, by default splunk checks the first 256 chars of a file to differentiate them. If you had a simple comment on the first line it will reindex it

  • change the crcSalt, create a new input for a new folder, add all the correct sourcetypes, etc... using a static string that will force a one time reindexing. crcSalt= REINDEXMEPLEASE

https://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html

View solution in original post

CarsonZa
Contributor

one of the following is what i use

  • modify the first line of the files to reindex, by default splunk checks the first 256 chars of a file to differentiate them. If you had a simple comment on the first line it will reindex it

  • change the crcSalt, create a new input for a new folder, add all the correct sourcetypes, etc... using a static string that will force a one time reindexing. crcSalt= REINDEXMEPLEASE

https://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html

tkwaller_2
Communicator

My only concern was with the data that was already there but it backfilled/reindexed just fine

Thanks again

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...