I'm trying to re-index some old data now that I've changed what index it goes into and
The data comes in from a UF that monitors two files.
These are the steps I took:
* | DELETE
splunk clean all
I'm now seeing data come correctly into the new index with the new source types, but there's no retrospective data - only new incoming data. Anyone know what I might be doing wrong?
We can re-index the data by modifying first line of the log file with some comments.
eg: #Re-index
so that crcSalt doen't match with other files and it re-indexes your data.
Hope it can help you.
All the best
does each event in your log file have a timestamp?
Unfortunately not. All the data I index has the indexing date as its time stamp. I've tried setting up a props.conf entry to specify the timestamp format for this sourcetype but it had no effect.
Did your resolution for your other issue solve this problem as well?
Yep, every line.