I need to reset the forwarder so it will read all my logs again and send them to the collector.
How can this be done?
Thank you.
On the forwarder machine, in Splunk's bin
directory: splunk clean eventdata -index _fishbucket
http://answers.splunk.com/answers/46780/reset-splunkforwarder-to-re-read-file-from-beginning