My search is that I have to log in the client machine, which needs to be ingested into Splunk Cloud- so I have deployed the inputs from deployment master and the app has successfully reached the client machine.
Actually the log which I have ingested is last updated on 8th Sep 2019, but I have done the configurations on today (11th Sep 2019) so when I search the data in Splunk Cloud I wasn't able to see the logs into Splunk Cloud.
So my search is so that the old data (8th Sep 2019) logs will be also ingested into Splunk Cloud?
If yes, then in my case why it's not getting ingested?
If no, then this is how the mechanism of Splunk works.
Kindly confirm the same.
Input Stanza:
[monitor:///ijk/lmn/otp.log]
sourcetype = xyz
index = abc
disabled = 0
So kindly help on the same.
... View more