<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data not ingested for only a few days in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123129#M25447</link>
    <description>&lt;P&gt;If the new file that gets placed there is "too similar" to the prior version, Splunk will refuse to index it on the belief that it already has. By "too similar" I mean "if the first &amp;lt;default&amp;gt; 256 bytes are the same". This size can be updated (see initCrcLength in inputs.conf).&lt;/P&gt;</description>
    <pubDate>Fri, 12 Sep 2014 21:03:48 GMT</pubDate>
    <dc:creator>sowings</dc:creator>
    <dc:date>2014-09-12T21:03:48Z</dc:date>
    <item>
      <title>Data not ingested for only a few days</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123126#M25444</link>
      <description>&lt;P&gt;I am facing a weird issue  ,A particular file has only been ingested for 4 days day even though we we have been receiving it for last 10 days .&lt;BR /&gt;
I looked the configuration , inputs.conf and props.conf , they are unchanged and the data got ingested yesterday as well .&lt;BR /&gt;
I have gone through the logs on the forwarder as well .&lt;BR /&gt;
Can you please tell me where I can look for error on indexers , or can there be any potential issue that someone can point out?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 18:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123126#M25444</guid>
      <dc:creator>ishugupta</dc:creator>
      <dc:date>2014-09-12T18:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Data not ingested for only a few days</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123127#M25445</link>
      <description>&lt;P&gt;More information please:&lt;/P&gt;

&lt;P&gt;Is ths &lt;EM&gt;new&lt;/EM&gt; contents on the same filename (i.e. a complete replacement)?&lt;/P&gt;

&lt;P&gt;Or is it continued additions to a single file? (i.e. same file growing larger day by day)&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 20:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123127#M25445</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2014-09-12T20:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Data not ingested for only a few days</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123128#M25446</link>
      <description>&lt;P&gt;we keep on placing new file each day.&lt;BR /&gt;
I researched more , I checked the log on the indexer license_usage.log , I can see the entry there...still I cant pull up the file on the console..&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 20:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123128#M25446</guid>
      <dc:creator>ishugupta</dc:creator>
      <dc:date>2014-09-12T20:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Data not ingested for only a few days</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123129#M25447</link>
      <description>&lt;P&gt;If the new file that gets placed there is "too similar" to the prior version, Splunk will refuse to index it on the belief that it already has. By "too similar" I mean "if the first &amp;lt;default&amp;gt; 256 bytes are the same". This size can be updated (see initCrcLength in inputs.conf).&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 21:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-not-ingested-for-only-a-few-days/m-p/123129#M25447</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2014-09-12T21:03:48Z</dc:date>
    </item>
  </channel>
</rss>

