I have created a new data input using files and directories option in splunk web.
I have put 3 excel files.
Later I have found some errors in files and I have deleted the host using host=A |delete command.
Later I try to recreated data source with same excel files.
This time host is not populating and displaying in search.
Any idea why this is happening.
It is happening because Splunk knows that it already read these files and will not index them twice. You can reset the file pointers for these files usingbtprobe
. Here is a good question/answer that describe this: