Getting Data In

Deleting Data Source.

jimjohn
Path Finder

I have created a new data input using files and directories option in splunk web.
I have put 3 excel files.
Later I have found some errors in files and I have deleted the host using host=A |delete command.
Later I try to recreated data source with same excel files.
This time host is not populating and displaying in search.
Any idea why this is happening.

Tags (5)
0 Karma

lguinn2
Legend

It is happening because Splunk knows that it already read these files and will not index them twice. You can reset the file pointers for these files usingbtprobe. Here is a good question/answer that describe this:

btprobe and re-indexing data

Documentation on btprobe

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...