Splunk disable and enable seems not to work on clusters. Seems only way to do it is to "move" the index. I do not like this as it means we are losing unknown data. Possible exploit here?
... View more
Note this does not work on Clusters, only fix I found was to stop splunk and move the file away. I do not like that as it means your losing data.
... View more