Deployment Architecture

How does Splunk forwarder handle data after uninstalling and reinstalling an app?

bruceclarke
Contributor

I have a bunch of forwarder machines that were inadvertently renamed recently. As a result, our forwarder manager no longer recognized the machines in the correct server class and apps were removed from the machine.

One of the apps that was removed forwards data from a file. Since the app was uninstalled and later reinstalled, will the forwarder resend data from that file? Or will it still remember which line was last forwarded and just pick up where it left off?

0 Karma
1 Solution

lguinn2
Legend

The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.

View solution in original post

lguinn2
Legend

The "file pointer" that tracks how far Splunk has read the input file is stored in the "fishbucket." The fishbucket is stored with the indexes. Unless you have deleted or reset the fishbucket in some way, the forwarder should pick up where it left off in processing the input.

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...