<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder missing log rotation in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-missing-log-rotation/m-p/103653#M21807</link>
    <description>&lt;P&gt;Hi romantercero&lt;/P&gt;

&lt;P&gt;there is a known bug if log file are being rotated with 'logadm -c', see &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Monitor on files stops indexing files if the file is truncated while calculating the CRC. (SPL-44773)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is fixed in 4.3.3&lt;/P&gt;

&lt;P&gt;cheers,&lt;/P&gt;

&lt;P&gt;MuS&lt;/P&gt;</description>
    <pubDate>Fri, 07 Sep 2012 12:47:01 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2012-09-07T12:47:01Z</dc:date>
    <item>
      <title>Forwarder missing log rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-missing-log-rotation/m-p/103652#M21806</link>
      <description>&lt;P&gt;I have noticed that some forwarders are not sending all of the log files. The log files are rotated hourly and I can see in the forwarder's log that it notices the log rotation and sends the file over. But once in a while it will not send it over and I can see that there is no corresponding event for that hour in the splunkd.log file on the forwarder stating that it has noticed a change in the log:&lt;/P&gt;

&lt;P&gt;03-26-2012 15:25:25.044 +0000 INFO  BatchReader - Removed from queue file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 15:49:11.554 +0000 INFO  BatchReader - Removed from queue file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 16:00:00.449 +0000 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 16:00:00.449 +0000 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 17:00:00.754 +0000 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 17:00:00.754 +0000 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 17:45:30.230 +0000 INFO  BatchReader - Removed from queue file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 18:00:00.148 +0000 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 18:00:00.148 +0000 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 19:10:42.208 +0000 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 19:10:42.208 +0000 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 21:00:55.261 +0000 INFO  BatchReader - Removed from queue file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 21:00:55.262 +0000 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 21:00:55.262 +0000 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 22:02:56.527 +0000 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;03-26-2012 22:02:56.527 +0000 INFO  WatchedFile - Will begin reading at offset=0 for &lt;BR /&gt;
file='/opt/ea/nova/nucleus/serv/nucleus.log'.&lt;/P&gt;

&lt;P&gt;You can see that there are no events for 20:00 and I can see the missing gap in the timeline when I do a search. &lt;/P&gt;

&lt;P&gt;Any thoughts? &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2012 22:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-missing-log-rotation/m-p/103652#M21806</guid>
      <dc:creator>romantercero</dc:creator>
      <dc:date>2012-03-28T22:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder missing log rotation</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-missing-log-rotation/m-p/103653#M21807</link>
      <description>&lt;P&gt;Hi romantercero&lt;/P&gt;

&lt;P&gt;there is a known bug if log file are being rotated with 'logadm -c', see &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Monitor on files stops indexing files if the file is truncated while calculating the CRC. (SPL-44773)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is fixed in 4.3.3&lt;/P&gt;

&lt;P&gt;cheers,&lt;/P&gt;

&lt;P&gt;MuS&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2012 12:47:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-missing-log-rotation/m-p/103653#M21807</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-09-07T12:47:01Z</dc:date>
    </item>
  </channel>
</rss>

