Hey there,
If we were to do a clean install of a Splunk forwarder (rip out previous version of forwarder), is there a way to retain/backup the previous forwarder's search information/history (CRC information??), so that the new forwarder will not re-index all of the log files from the directory the previous forwarder was monitoring?
We do not want to do an in place upgrade of the forwarder, but rip of the old version and install a newer version of the forwarder, without having to re-index all of the log files the old forwarder would have already processed. Or, is this information (the crc) saved in the indexer?
Thanks for your time.
Usup
↧