Splunk Search

Reindex a file on 3000 machines

daniel333
Builder

All,

I indexed a 30-line config file off all our Linux hosts. But accidentally used the wrong source-type and index. So I deleted the delete with | delete. Now I need to reindex the file now that I have the correct inputs.conf configured. I thought it would as simple as adding

crcsalt= and I'd be set. But it's not working. Any ideas?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can change the init CRC length in your inputs.conf, that will invalidate all fishbucket entries you previously had.

martin_mueller
SplunkTrust
SplunkTrust

A 30-line config file should be long enough for a 256b CRC - that's just eight byte per line.

Note, configuration keys are case sensitive. Make sure you used crcSalt and initCrcLength as specified in inputs.conf.

0 Karma

gjanders
SplunkTrust
SplunkTrust
0 Karma

daniel333
Builder

Tried this with no luck. I suspect since this file is very tiny that the CRC init might not play a factor but I am honestly not sure. Any other tricks?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...