<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs were not indexing in Splunk from a particular path in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239064#M46446</link>
    <description>&lt;P&gt;The logs from the source="/tpo/jboss/server/shared/logs/*cap/server.log" were not properly getting into the index and i continuously seeing the following logs in the splunkd.log everyday at 1 A.M &lt;/P&gt;

&lt;P&gt;INFO  WatchedFile - Will begin reading at offset=0 for file="/tpo/jboss/server/shared/logs/*cap/server.log" &lt;BR /&gt;
INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file="/tpo/jboss/server/shared/logs/*cap/server.log" &lt;BR /&gt;
 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file="/tpo/jboss/server/shared/logs/*cap/server.log" &lt;/P&gt;

&lt;P&gt;Please do suggest what needs to be done to get those logs&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:22:05 GMT</pubDate>
    <dc:creator>pavanae</dc:creator>
    <dc:date>2020-09-29T07:22:05Z</dc:date>
    <item>
      <title>Logs were not indexing in Splunk from a particular path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239064#M46446</link>
      <description>&lt;P&gt;The logs from the source="/tpo/jboss/server/shared/logs/*cap/server.log" were not properly getting into the index and i continuously seeing the following logs in the splunkd.log everyday at 1 A.M &lt;/P&gt;

&lt;P&gt;INFO  WatchedFile - Will begin reading at offset=0 for file="/tpo/jboss/server/shared/logs/*cap/server.log" &lt;BR /&gt;
INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file="/tpo/jboss/server/shared/logs/*cap/server.log" &lt;BR /&gt;
 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file="/tpo/jboss/server/shared/logs/*cap/server.log" &lt;/P&gt;

&lt;P&gt;Please do suggest what needs to be done to get those logs&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239064#M46446</guid>
      <dc:creator>pavanae</dc:creator>
      <dc:date>2020-09-29T07:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Logs were not indexing in Splunk from a particular path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239065#M46447</link>
      <description>&lt;P&gt;Missed the Following log to mention in the above question.&lt;/P&gt;

&lt;P&gt;ERROR TailingProcessor - File will not be read, seekptr checksum did not match (file=/tpo/jboss/server/shared/logs/*cap/server.log).  Last time we saw this initcrc, filename was different.  You may wish to use a CRC salt on this source.  Consult the documentation or file a support case online at&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 15:29:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239065#M46447</guid>
      <dc:creator>pavanae</dc:creator>
      <dc:date>2015-09-24T15:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Logs were not indexing in Splunk from a particular path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239066#M46448</link>
      <description>&lt;P&gt;Above error means that the initcrc handler (default first 250 bytes of the file) which Splunk uses to identify a file that needs monitoring is not unique and it's not going to ingest the data.&lt;/P&gt;

&lt;P&gt;How is the file generated and does it have a common header at the start which will be same for every file/copy of the file?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 19:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239066#M46448</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-09-24T19:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Logs were not indexing in Splunk from a particular path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239067#M46449</link>
      <description>&lt;P&gt;This happened due to the permission issues on the particular paths in the forwarder. It got resolved after providing the required permissions for those paths.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 14:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-were-not-indexing-in-Splunk-from-a-particular-path/m-p/239067#M46449</guid>
      <dc:creator>pavanae</dc:creator>
      <dc:date>2016-09-07T14:49:29Z</dc:date>
    </item>
  </channel>
</rss>

