<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;amp;quot;INFO WatchedFile - Resetting fd to re-extract header&amp;amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/614492#M106328</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;one reason for that could be that UF needs to read those header names again and again to send that information with events. Can you try to add FIELD_NAMES= ..... to your props.conf to avoid that?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 07:30:23 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-09-26T07:30:23Z</dc:date>
    <item>
      <title>&amp;quot;INFO WatchedFile - Resetting fd to re-extract header&amp;quot;?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/614447#M106321</link>
      <description>&lt;P&gt;I have the csv file which has the below lines.&lt;/P&gt;
&lt;P&gt;=========================&lt;/P&gt;
&lt;P&gt;METRIC_NAME,METRIC_UNIT,BEGIN_TIME,END_TIME,MAXVAL,MINVAL,AVERAGE&lt;BR /&gt;&lt;BR /&gt;Buffer Cache Hit Ratio,% (LogRead - PhyRead)/LogRead,09/25/2022 14:59,09/25/2022 15:59,100,0,100&lt;BR /&gt;Memory Sorts Ratio,% MemSort/(MemSort + DiskSort),09/25/2022 14:59,09/25/2022 15:59,100,0,100&lt;BR /&gt;Redo Allocation Hit Ratio,% (#Redo - RedoSpaceReq)/#Redo,09/25/2022 14:59,09/25/2022 15:59,100,0,100&lt;BR /&gt;User Transaction Per Sec,Transactions Per Second,09/25/2022 14:59,09/25/2022 15:59,1.383,0,.528&lt;BR /&gt;Physical Reads Per Sec,Reads Per Second,09/25/2022 14:59,09/25/2022 15:59,1.05,0,.138&lt;BR /&gt;Physical Reads Per Txn,Reads Per Txn,09/25/2022 14:59,09/25/2022 15:59,2.296,0,.223&lt;/P&gt;
&lt;P&gt;-----160 lines&lt;/P&gt;
&lt;P&gt;I have modified the header , inputs.conf &amp;amp;props.conf but still the mentioned error has seen.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Inputs.conf:&lt;/P&gt;
&lt;P&gt;[monitor:///u01/app/oracle/scripts/Performance_metrics/output]&lt;BR /&gt;disabled = false&lt;BR /&gt;index=brm_db&lt;BR /&gt;initCrcLength=2048&lt;BR /&gt;sourcetype = csv&lt;BR /&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Props.conf:&lt;/P&gt;
&lt;P&gt;[csv]&lt;BR /&gt;SHOULD_LINEMERGE = False&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;category = custom&lt;BR /&gt;HEADER_FIELD_ACCEPTABLE_SPECIAL_CHARACTERS=_&lt;BR /&gt;HEADER_FIELD_DELIMITER=,&lt;BR /&gt;FIELD_DELIMITER=,&lt;BR /&gt;description = Comma-separated value format. Set header and other settings in "Delimited Settings"&lt;/P&gt;
&lt;P&gt;Can someone help with this as i need to complete it ASAP. Stuck for almost 2 days with this. Quickly help can be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 15:23:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/614447#M106321</guid>
      <dc:creator>yuvasree</dc:creator>
      <dc:date>2022-09-26T15:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: &amp;quot;INFO WatchedFile - Resetting fd to re-extract header&amp;quot;</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/614492#M106328</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;one reason for that could be that UF needs to read those header names again and again to send that information with events. Can you try to add FIELD_NAMES= ..... to your props.conf to avoid that?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 07:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/614492#M106328</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-09-26T07:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: &amp;quot;INFO WatchedFile - Resetting fd to re-extract header&amp;quot;</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/616840#M106537</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Actually again in one server for another output same kind of error seen.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;As you recommended I can't set the field names as I have 40 files under the same folder and also the common thing is all these are SQL outputs. Can someone help me with this error as this is blocking the full work .&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I tried too many settings nothing helped.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt; @gcusello&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 17:03:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/amp-quot-INFO-WatchedFile-Resetting-fd-to-re-extract-header-amp/m-p/616840#M106537</guid>
      <dc:creator>yuvasree</dc:creator>
      <dc:date>2022-10-12T17:03:20Z</dc:date>
    </item>
  </channel>
</rss>

