Monitoring Splunk

If you change the index attribute of monitor stanza in inputs.conf, Will log re-capture be done?

takashiscsk
New Member

If you change the index attribute of monitor stanza in inputs.conf,
Will log re-capture be done?

For example, if you change it as below in inputs.conf

Change before

[monitor: ///work/file.txt]
index = test 0612
sourcetype = sample

After change

[monitor: ///work/file.txt]
index = test 0613
sourcetype = sample

Tags (1)
0 Karma

Ayn
Legend

No, because Splunk instances (including forwarders) use their internal _fishbucket index for keeping track of positions in files they're indexing. You'd have to clean that out one way or another to make Splunk reindex data.

0 Karma

ddrillic
Ultra Champion

Nope, in cases like these, I sometimes drop the forwarder and re-install it. Starting fresh ; -)

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...