<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Error reading compressed journal while streaming: gzip data truncated&amp;quot;. Are my Hadoop archived buckets corrupted, and how do I fix it? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284509#M10793</link>
    <description>&lt;P&gt;I am having this same issue - v7.2.1.  Has there been any progress on a fix for this?&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2019 16:54:09 GMT</pubDate>
    <dc:creator>gurlest</dc:creator>
    <dc:date>2019-05-10T16:54:09Z</dc:date>
    <item>
      <title>"Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284505#M10789</link>
      <description>&lt;P&gt;While running a query via EMR on a bucket archived to s3 with hadoop data roll, I got the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[hadoop] [ip-192-168-4-184] Streamed search execute failed because: Error reading compressed journal while streaming: gzip data truncated, provider=StdinGzDataProvider
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Does this mean that one of the archived journal.gz files is corrupt? If so:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;How can I figure out how it got corrupted?&lt;/LI&gt;
&lt;LI&gt;How do I figure out which one and fix it?
This is still in test phase, so I have all the archived buckets on my indexer still. I'm trying to validate that the archival mechanism is safe and reliable.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 28 Oct 2016 20:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284505#M10789</guid>
      <dc:creator>heroku_curzonj</dc:creator>
      <dc:date>2016-10-28T20:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: "Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284506#M10790</link>
      <description>&lt;P&gt;"Streamed search execute failed because: Error reading compressed journal while streaming: gzip data truncated, provider=StdinGzDataProvider" error is because one or more of the archived journal.gz are corrupted.&lt;/P&gt;

&lt;P&gt;If splunk suffers crash or an unclean shutdown (power loss, hardware failure, OS failure, etc) then some buckets can be left in a bad state where not all data is searchable. If bucket is corrupted locally on indexer, then archived bucket will also be corrupted.&lt;/P&gt;

&lt;P&gt;Local splunk buckets can be fixed by following these instructions : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Bucketissues"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Bucketissues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Currently there is no way to fix corrupted journal.gz that are archived. We are working on fix, that will ensure that we read data from corrupted journal till we hit corrupted part of the journal. We will log error message in search.log suggesting that particular journal is corrupted. This fix will be available in future release.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 21:37:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284506#M10790</guid>
      <dc:creator>kpawar_splunk</dc:creator>
      <dc:date>2016-10-28T21:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: "Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284507#M10791</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have been unable to locate any future updates on this topic ?&lt;BR /&gt;
We are running 7.2.1 and I would like to know if there is still no way to fix a corrupt archived journal.gz file &lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Paul&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 13:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284507#M10791</guid>
      <dc:creator>pbrinkman</dc:creator>
      <dc:date>2018-12-13T13:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: "Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284508#M10792</link>
      <description>&lt;P&gt;Has there been any progress?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 19:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284508#M10792</guid>
      <dc:creator>jmantor</dc:creator>
      <dc:date>2018-12-26T19:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: "Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284509#M10793</link>
      <description>&lt;P&gt;I am having this same issue - v7.2.1.  Has there been any progress on a fix for this?&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 16:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284509#M10793</guid>
      <dc:creator>gurlest</dc:creator>
      <dc:date>2019-05-10T16:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: "Error reading compressed journal while streaming: gzip data truncated". Are my Hadoop archived buckets corrupted, and how do I fix it?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284510#M10794</link>
      <description>&lt;P&gt;hi Gurlest,  No update has been provided by Splunk or any of the users from Splunk answers.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 14:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/quot-Error-reading-compressed-journal-while-streaming-gzip-data/m-p/284510#M10794</guid>
      <dc:creator>pbrinkman</dc:creator>
      <dc:date>2019-05-13T14:14:54Z</dc:date>
    </item>
  </channel>
</rss>

