<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WatchedFile - Will begin reading at offset in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72725#M14830</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a weird issue with a bunch of files that I have recently started indexing. A whole bunch of these will end up in the index with missing events (typically missing 1 or 2 events).&lt;/P&gt;

&lt;P&gt;For these files I'm seeing reports like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-27-2012 11:08:05.908 +0300 INFO  WatchedFile - Will begin reading at offset=253 for file='/path/to/file.log'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Why does the forwarder skip events like this?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Sep 2012 09:24:54 GMT</pubDate>
    <dc:creator>echalex</dc:creator>
    <dc:date>2012-09-27T09:24:54Z</dc:date>
    <item>
      <title>WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72725#M14830</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a weird issue with a bunch of files that I have recently started indexing. A whole bunch of these will end up in the index with missing events (typically missing 1 or 2 events).&lt;/P&gt;

&lt;P&gt;For these files I'm seeing reports like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-27-2012 11:08:05.908 +0300 INFO  WatchedFile - Will begin reading at offset=253 for file='/path/to/file.log'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Why does the forwarder skip events like this?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 09:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72725#M14830</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2012-09-27T09:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72726#M14831</link>
      <description>&lt;P&gt;Are you using the option ?&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
followTail=true&lt;BR /&gt;
&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;this option is misleading and for rotating files cause the offset to not start at 0, see &lt;A href="http://splunk-base.splunk.com/answers/57819/when-is-it-appropriate-to-set-followtail-to-true"&gt;http://splunk-base.splunk.com/answers/57819/when-is-it-appropriate-to-set-followtail-to-true&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please remove it.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 15:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72726#M14831</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-09-27T15:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72727#M14832</link>
      <description>&lt;P&gt;Nope, I'm not using followTail=true, because I know - by experience - that it's not a good idea.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 06:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72727#M14832</guid>
      <dc:creator>echalex</dc:creator>
      <dc:date>2012-09-28T06:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72728#M14833</link>
      <description>&lt;P&gt;hey brother i got some same issue now for the past 2 days. the whole app i developed is not working. please let me know if you know the answer&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 08:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72728#M14833</guid>
      <dc:creator>eashwar</dc:creator>
      <dc:date>2013-05-10T08:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72729#M14834</link>
      <description>&lt;P&gt;I assume the log files are rotating? Do you know where in your log files the missing messages would have been?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2013 07:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72729#M14834</guid>
      <dc:creator>BenAveling</dc:creator>
      <dc:date>2013-09-06T07:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72730#M14835</link>
      <description>&lt;P&gt;We've observed the same behaviour, in our case the cause was the tailing process does duplication detection with a checksum on the first and last 256 bytes of a file (so as to not index the same file twice).&lt;/P&gt;

&lt;P&gt;We had two files with identical content being monitored. &lt;/P&gt;

&lt;P&gt;Our resolution was to use crcSalt = A and crcSalt = B in each stanza which ensured they had differing checksums (we could do this because the duplicate files were listed in two different monitor stanzas).&lt;/P&gt;

&lt;P&gt;You should also beware of changing the crcSalt on a running system as it will cause previously indexed files to be re-indexed.&lt;/P&gt;

&lt;P&gt;Over a 10 minute window our splunkd.log looked like;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;INFO  WatchedFile - Will begin reading at offset=1575 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=1890 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=2115 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=2205 for file='/tmp/logtset/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=2340 for file='/tmp/logtset/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=2700 for file='/tmp/logtset/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=2970 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=5490 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=6795 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=7560 for file='/tmp/logtest/test_2013101419.log'.
INFO  WatchedFile - Will begin reading at offset=9810 for file='/tmp/logtset/test_2013101419.log'.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 15 Oct 2013 20:40:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72730#M14835</guid>
      <dc:creator>matthew_lawrenc</dc:creator>
      <dc:date>2013-10-15T20:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72731#M14836</link>
      <description>&lt;P&gt;Thanks for this.  I experiencing this as well, however my log files are not completely the same...I have something like the following:&lt;/P&gt;

&lt;P&gt;WatchedFile - Will begin reading at offset=&lt;SOMENUMBER&gt; for file='/log/path/1/logs/file.log&lt;/SOMENUMBER&gt;&lt;/P&gt;

&lt;P&gt;WatchedFile - Will begin reading at offset=&lt;SOMENUMBER&gt; for file='/log/path/2/logs/file.log&lt;/SOMENUMBER&gt;&lt;/P&gt;

&lt;P&gt;The log paths are slightly different, but the log file names are the same.  I am also already using crcSalt, but this just began 3 days ago.  Still no solution found&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 17:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72731#M14836</guid>
      <dc:creator>_gkollias</dc:creator>
      <dc:date>2014-08-08T17:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: WatchedFile - Will begin reading at offset</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72732#M14837</link>
      <description>&lt;P&gt;FYI - "Do not use crcSalt = with rolling log files, or any other scenario in which logfiles get renamed or moved to another monitored location. Doing so prevents Splunk Enterprise from recognizing log files across the roll or rename, which results in the data being reindexed."&lt;/P&gt;

&lt;P&gt;From: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.3/Data/Howlogfilerotationishandled"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.3/Data/Howlogfilerotationishandled&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 19:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchedFile-Will-begin-reading-at-offset/m-p/72732#M14837</guid>
      <dc:creator>markbarber21</dc:creator>
      <dc:date>2018-07-31T19:50:01Z</dc:date>
    </item>
  </channel>
</rss>

