Splunk Cloud Platform

Why is my past data not being forwarded (Cloud vs Free Instance trial)?

cdhgold
Engager

I setup a trial of the free Splunk Cloud instance to receive data from my web server and it sent in not only the current data but also the historical data so that I could do searches back to when the apache logs were started.

Today I installed the Splunk Free on a separate system and configured the web server to forward to it instead of the Splunk Cloud instance.

my new install is getting current live data but it is not getting the historical data to be able to do year to date searches , etc..

Did I miss something or is it a limit of the type of splunk install ( Free vs Cloud Instance Trial? )

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The forwarder keeps track of what it's sent to be indexed so data is not duplicated (with a corresponding effect on your license). Changing the target of the forwarding does not tell the forwarder to re-index historical data.

To force the forwarder to re-index historical data you'll need to clear the "fishbucket". See https://answers.splunk.com/answers/612608/how-to-re-index-data-in-a-different-index.html

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...