All,
I indexed a 30-line config file off all our Linux hosts. But accidentally used the wrong source-type and index. So I deleted the delete with | delete. Now I need to reindex the file now that I have the correct inputs.conf configured. I thought it would as simple as adding
crcsalt= and I'd be set. But it's not working. Any ideas?
You can change the init CRC length in your inputs.conf, that will invalidate all fishbucket entries you previously had.
A 30-line config file should be long enough for a 256b CRC - that's just eight byte per line.
Note, configuration keys are case sensitive. Make sure you used crcSalt
and initCrcLength
as specified in inputs.conf.
if you just want to ingest this file once off than perhaps oneshot? As per https://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI
Tried this with no luck. I suspect since this file is very tiny that the CRC init might not play a factor but I am honestly not sure. Any other tricks?