Monitoring Splunk

How can I re-index license-usage.log?

tkwaller_2
Communicator

Hello

Someone prior to me had set the license master to forward logs to the wrong hosts so when I fixed it I have no historical data for license usage.
Whats the best way to fix this?

Thanks for the assistance!

0 Karma
1 Solution

CarsonZa
Contributor

one of the following is what i use

  • modify the first line of the files to reindex, by default splunk checks the first 256 chars of a file to differentiate them. If you had a simple comment on the first line it will reindex it

  • change the crcSalt, create a new input for a new folder, add all the correct sourcetypes, etc... using a static string that will force a one time reindexing. crcSalt= REINDEXMEPLEASE

https://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html

View solution in original post

CarsonZa
Contributor

one of the following is what i use

  • modify the first line of the files to reindex, by default splunk checks the first 256 chars of a file to differentiate them. If you had a simple comment on the first line it will reindex it

  • change the crcSalt, create a new input for a new folder, add all the correct sourcetypes, etc... using a static string that will force a one time reindexing. crcSalt= REINDEXMEPLEASE

https://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html

tkwaller_2
Communicator

My only concern was with the data that was already there but it backfilled/reindexed just fine

Thanks again

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...