Hy, i've a free Version for Linux, and i've a problem when i try to delete all eventData via CLI with: ./splunk clean eventdata It needs to stop splunk, but if i stop splunk, i'll lost all logs during the reboot. How can i resolve it, is there a solution???? Thanks
Hai There,
To avoid dataloss during restarts of an indexer you have to take a look at putting a forwarder in front.
cheers Starlette
Sorry, the forwarders solution is excellent, but not good yet when you have a lot of machines, in fact, each forwarder must be installed on every system which you would receive logs. Is it right?