<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor a File That's Being Purged Regularly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-File-That-s-Being-Purged-Regularly/m-p/253902#M48736</link>
    <description>&lt;P&gt;I found the root cause of this already. The file that was being monitored was just too big for the default bandwidth limit of the forwarder. &lt;/P&gt;

&lt;P&gt;I modified the maxKbps in limits.conf to adjust it and accommodate the volume.&lt;/P&gt;

&lt;P&gt;I hope this helps someone someday.&lt;/P&gt;

&lt;P&gt;Kindest regards,&lt;BR /&gt;
Jef&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2016 11:00:47 GMT</pubDate>
    <dc:creator>jepoyyyy</dc:creator>
    <dc:date>2016-10-10T11:00:47Z</dc:date>
    <item>
      <title>Monitor a File That's Being Purged Regularly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-File-That-s-Being-Purged-Regularly/m-p/253901#M48735</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have a multi-tiered Splunk deployment and I am having some serious indexing lag from a remote host. &lt;/P&gt;

&lt;P&gt;We have configured a forwarder to monitor a file that is being purged every 30 minutes. After the said interval, the contents of the file are being written in an archive directory. The problem is, we have a significant amount of lag before it becomes searchable in Splunk. We sometimes experience as far as 5 hour indexing lag from that particular source. Upon checking on it now, it is down to 45 minutes lag. So the lag varies from time to time.&lt;/P&gt;

&lt;P&gt;We're pretty sure that it is not being caused by an undersized Splunk infrastracture because we are also collecting *nix stats (cpu, ram, disk, etc) and these events come in in near-realtime.&lt;/P&gt;

&lt;P&gt;Upon checking the logs from the forwarder, we see this line from time to time.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;WatchedFile - Checksum for seekptr didn't match, will re-read entire file="/some/file/name/file.log".&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Is there an inputs.conf parameter that I should make use to monitor a file that is being flushed regularly? &lt;/P&gt;

&lt;P&gt;Any help would greatly be appreciated. &lt;/P&gt;

&lt;P&gt;Kindest regards,&lt;BR /&gt;
Jeff&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 06:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-File-That-s-Being-Purged-Regularly/m-p/253901#M48735</guid>
      <dc:creator>jepoyyyy</dc:creator>
      <dc:date>2016-08-30T06:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a File That's Being Purged Regularly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-File-That-s-Being-Purged-Regularly/m-p/253902#M48736</link>
      <description>&lt;P&gt;I found the root cause of this already. The file that was being monitored was just too big for the default bandwidth limit of the forwarder. &lt;/P&gt;

&lt;P&gt;I modified the maxKbps in limits.conf to adjust it and accommodate the volume.&lt;/P&gt;

&lt;P&gt;I hope this helps someone someday.&lt;/P&gt;

&lt;P&gt;Kindest regards,&lt;BR /&gt;
Jef&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 11:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-File-That-s-Being-Purged-Regularly/m-p/253902#M48736</guid>
      <dc:creator>jepoyyyy</dc:creator>
      <dc:date>2016-10-10T11:00:47Z</dc:date>
    </item>
  </channel>
</rss>

