<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring of files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669589#M112269</link>
    <description>&lt;P&gt;You can check the status of your inputs with&lt;/P&gt;&lt;PRE&gt;splunk list monitor&lt;/PRE&gt;&lt;P&gt;and&lt;/P&gt;&lt;PRE&gt;splunk list inputstatus&lt;/PRE&gt;</description>
    <pubDate>Thu, 23 Nov 2023 19:18:52 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2023-11-23T19:18:52Z</dc:date>
    <item>
      <title>Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669445#M112248</link>
      <description>&lt;P&gt;Hello, I´m trying to resolve monitoring issue of available .csv files of specific directory. There are several files marked by different date e.g. 2023-11-16_filename.csv or 2023-11-20_filename.csv.&lt;BR /&gt;None of them has the same date at the beginning for this reason. I´m able synch with the server most of the files but there are some which I´m not. For example my indexing started on 02.10.23 and all the files matching or later are available as source. But all the files before this date are not e.g. 2023-09-15_filename.csv.&lt;BR /&gt;What could cause this performance and is there a way how to push files to available as a source even they marked with the date before 02.10.2023 ? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 10:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669445#M112248</guid>
      <dc:creator>Stives</dc:creator>
      <dc:date>2023-11-22T10:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669449#M112249</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223397"&gt;@Stives&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;How does your Inputstanza looks like?&lt;BR /&gt;If no crcSalt is specified in the stanza, Splunk will look into the first (i think 256) Bytes of a file and determines based on that if it already know the File.&lt;BR /&gt;If the first Bytes in the CSV files will always be the same you could change your inputstanza and add&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;docs to monitoring stanza for a deeper look into crcSalt:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf#MONITOR" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf#MONITOR&lt;/A&gt;:&lt;BR /&gt;&lt;BR /&gt;But be cautious, this will tell splunk to watch for the full path to determine if this file is already been indexed, so there is a possibility that you index the same file twice. Especially for Directories with rolling logfiles.&lt;BR /&gt;&lt;BR /&gt;Other possibility could be that the dates are out of the retention time scope. (If the files got indexed once but due to retention time got removed again when its bucket is not hot anymore)&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 10:53:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669449#M112249</guid>
      <dc:creator>TheEggi98</dc:creator>
      <dc:date>2023-11-22T10:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669553#M112260</link>
      <description>&lt;P&gt;Hello, thanks for reply.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/PRE&gt;&lt;P&gt;I´ve been adding crcSalt into my stanza but still the not all the files have been synced either.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 09:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669553#M112260</guid>
      <dc:creator>Stives</dc:creator>
      <dc:date>2023-11-23T09:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669556#M112261</link>
      <description>&lt;P&gt;crcSalt is actually very rarely the proper option to set. It's often better to raise the initCrcLength to a higher value in case the file has a pretty constant header.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 10:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669556#M112261</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-23T10:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669561#M112262</link>
      <description>&lt;P&gt;Hello I see. You mean anything like this ?&lt;/P&gt;&lt;PRE&gt;initCrcLength = &amp;lt;256&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 11:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669561#M112262</guid>
      <dc:creator>Stives</dc:creator>
      <dc:date>2023-11-23T11:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669562#M112263</link>
      <description>&lt;P&gt;Close. But without the &amp;lt;&amp;gt; part (the &amp;lt;SOURCE&amp;gt; part must be literally put this way if you use this option). And you'd typically want a higher value if you have a constant header.&lt;/P&gt;&lt;P&gt;Something like&lt;/P&gt;&lt;PRE&gt;initCrcLength = 1024&lt;/PRE&gt;&lt;P&gt;for example.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 11:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669562#M112263</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-23T11:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669576#M112264</link>
      <description>&lt;P&gt;Thanks for reply. I´ve tried with the option:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;initCrcLength = 1024&lt;/PRE&gt;&lt;P&gt;But still not all the files have been synced. There are still more pending.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 14:43:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669576#M112264</guid>
      <dc:creator>Stives</dc:creator>
      <dc:date>2023-11-23T14:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669577#M112265</link>
      <description>&lt;P&gt;One more. I was checking and one of the files has more than&amp;nbsp; 124 000 bytes. What value I should define for initCrcLenght ?&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 15:11:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669577#M112265</guid>
      <dc:creator>Stives</dc:creator>
      <dc:date>2023-11-23T15:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669589#M112269</link>
      <description>&lt;P&gt;You can check the status of your inputs with&lt;/P&gt;&lt;PRE&gt;splunk list monitor&lt;/PRE&gt;&lt;P&gt;and&lt;/P&gt;&lt;PRE&gt;splunk list inputstatus&lt;/PRE&gt;</description>
      <pubDate>Thu, 23 Nov 2023 19:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669589#M112269</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-23T19:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669613#M112271</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Are you sure that you haven't set this?&lt;/P&gt;&lt;PRE&gt;ignoreOlderThan&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Can you post your inputs.conf for this source, so we can check if there is something else which can cause this behaviour?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 06:40:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669613#M112271</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-24T06:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669619#M112273</link>
      <description>&lt;P&gt;Hello Ismo,&lt;/P&gt;&lt;P&gt;inputs.conf definition looks like this:&lt;BR /&gt;&lt;BR /&gt;[monitor:///home/sicpa_operator/deploy/PROD/machine/monitoring/*production_statistics.csv]&lt;BR /&gt;index = sts&lt;BR /&gt;disabled = false&lt;BR /&gt;sourcetype = STSLOGMPPS&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;&lt;BR /&gt;by *production_statistics.csv I make sure all the files have to be synced they only contain different dates at the beginning of each file name. Seems I´m able sync only the files by the deployment date. Means files from date when UF been deployed are synced but the everything before not.&lt;BR /&gt;BR&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 08:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669619#M112273</guid>
      <dc:creator>Stives</dc:creator>
      <dc:date>2023-11-24T08:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669636#M112275</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about outputs of&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk list inputstatus&lt;/LI-CODE&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;asked? That command shows what files it has read and how much has managed.&lt;/P&gt;&lt;P&gt;Also you could try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list monitor:///home/sicpa_operator/deploy/PROD/machine/monitoring/ --debug&lt;/LI-CODE&gt;&lt;P&gt;to see if there is somewhere defined some weird defaults for your inputs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 12:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-of-files/m-p/669636#M112275</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-24T12:23:16Z</dc:date>
    </item>
  </channel>
</rss>

