Getting Data In

Trouble re-creating sourcetype after delete

lain179
Communicator

I created some incorrect logs with the command

  • sourcetype="DS Logs" | delete

I have can_delete permission, and the process went through without any error. Then I changed input and transforms conf files and restarted Splunk to grab correct logs, but nothing happened. I can't clean the index because I need the data in that index that belong to other sourcetypes.

Please advise.

I cannot add new source or sourcetype and monitoring the DS sourcetype doesn't work anymore

Tags (1)
0 Karma
1 Solution

lain179
Communicator

Never mind. It's working now. The server TCP connection had an issue and that's why it's not updating the monitored logs.

0 Karma

lain179
Communicator

This command solves my problem of re-adding the same logs

./splunk add oneshot /full/path/to/file -sourcetype mysourcetype -index myindex -host myhostparam

But I have new sourcetypes, and they are not going into Splunk either. What else do I have to do?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...