Splunk Dev

Checkpoint Modular Input cleanup Side effects

NHLaurent72
Engager

Hi All,

We are want the run a modular input cleanup. What happens to the checkpoints? Will ingest from start from beginning again?

 

Thanks

Nick

0 Karma

NHLaurent72
Engager

Yes that's right. Ok, I'll give that go.

Thanks

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

what you are meaning with "run a modular input cleanup"? If this means also remove checkpoint value then the ingestion starts from scratch (read: from being of existent events). At some TAs you could see and copy checkpoint value e.g. to text file. After cleanup it may be possible to add old values back and continue from that point. But this is depending on TA. 

r. Ismo

Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...