Getting Data In

How to reset the forwarder to read all logs again and send them to the receiver?

cmlombardo
Path Finder

I need to reset the forwarder so it will read all my logs again and send them to the collector.
How can this be done?

Thank you.

Tags (1)
0 Karma

Ayn
Legend

On the forwarder machine, in Splunk's bin directory: splunk clean eventdata -index _fishbucket

http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning

Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...