Getting Data In

Unable to re-index all data

Deecie
Explorer

I'm trying to re-index some old data now that I've changed what index it goes into and

The data comes in from a UF that monitors two files.

These are the steps I took:

  • Stopped the forwarder
  • Ran this on the indexer:

* | DELETE

  • ran this on the forwarder; my understanding is that it should clear the _fishbucket index:

splunk clean all

  • made my config changes
  • started the forwarder

I'm now seeing data come correctly into the new index with the new source types, but there's no retrospective data - only new incoming data. Anyone know what I might be doing wrong?

Tags (1)
0 Karma

neelamssantosh
Contributor

We can re-index the data by modifying first line of the log file with some comments.
eg: #Re-index
so that crcSalt doen't match with other files and it re-indexes your data.

Hope it can help you.
All the best

0 Karma

cramasta
Builder

does each event in your log file have a timestamp?

0 Karma

Deecie
Explorer

Unfortunately not. All the data I index has the indexing date as its time stamp. I've tried setting up a props.conf entry to specify the timestamp format for this sourcetype but it had no effect.

0 Karma

araitz
Splunk Employee
Splunk Employee

Did your resolution for your other issue solve this problem as well?

0 Karma

Deecie
Explorer

Yep, every line.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...