Dear All,
We have retrieve datas from salesforce with Splunk Add-On for salesforece. However, we missed out some critical fields so we have to | delete all data and reload data from scatches. However, since the same Forwarder is connected to O365 so we cannot reset the reading pointer by splunk clean all.
Do you have any recommendation so we could reset the Splunk TA for salesforce and reload the data from begining?
If you're talking about having the Inputs pull the data again, the checkpoint info is stored here $SPLUNK_HOME/var/lib/splunk/modinputs/sfdc_object.
You can go there and delete the individual directories/files or just the ones you want to reset.