<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk not indexing the entire file. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-indexing-the-entire-file/m-p/28819#M4952</link>
    <description>&lt;P&gt;I have a new 5.0 splunk server that is the indexer and search head.&lt;BR /&gt;
I have one forwarder sending logs.&lt;BR /&gt;
All is working well but!&lt;BR /&gt;
One directory of log files. Splunk is only reading the first line of the files in this directory.&lt;BR /&gt;
The splunkd.log &lt;/P&gt;

&lt;P&gt;11-09-2012 08:33:43.250 -0600 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jrun4/logs/server-2-event.log'.&lt;/P&gt;

&lt;P&gt;11-09-2012 08:33:43.250 -0600 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/jrun4/logs/server-2-event.log'.&lt;/P&gt;

&lt;P&gt;Here is what is in my inputs.conf&lt;/P&gt;

&lt;P&gt;[monitor:///opt/jrun4/logs]&lt;/P&gt;

&lt;P&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;I just recently add the crcSalt = &amp;lt;SOURCE&amp;gt; and restarted the forwarder. I'm still not getting the entire file indexed.&lt;/P&gt;

&lt;P&gt;NOTE: I do have the word "SOURCE"  between the greater than and less than symbols. It just didn't show up when typeing this question.&lt;/P&gt;

&lt;P&gt;Please help.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2012 14:54:03 GMT</pubDate>
    <dc:creator>khhenderson</dc:creator>
    <dc:date>2012-11-09T14:54:03Z</dc:date>
    <item>
      <title>Splunk not indexing the entire file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-indexing-the-entire-file/m-p/28819#M4952</link>
      <description>&lt;P&gt;I have a new 5.0 splunk server that is the indexer and search head.&lt;BR /&gt;
I have one forwarder sending logs.&lt;BR /&gt;
All is working well but!&lt;BR /&gt;
One directory of log files. Splunk is only reading the first line of the files in this directory.&lt;BR /&gt;
The splunkd.log &lt;/P&gt;

&lt;P&gt;11-09-2012 08:33:43.250 -0600 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jrun4/logs/server-2-event.log'.&lt;/P&gt;

&lt;P&gt;11-09-2012 08:33:43.250 -0600 INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/jrun4/logs/server-2-event.log'.&lt;/P&gt;

&lt;P&gt;Here is what is in my inputs.conf&lt;/P&gt;

&lt;P&gt;[monitor:///opt/jrun4/logs]&lt;/P&gt;

&lt;P&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;I just recently add the crcSalt = &amp;lt;SOURCE&amp;gt; and restarted the forwarder. I'm still not getting the entire file indexed.&lt;/P&gt;

&lt;P&gt;NOTE: I do have the word "SOURCE"  between the greater than and less than symbols. It just didn't show up when typeing this question.&lt;/P&gt;

&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 14:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-indexing-the-entire-file/m-p/28819#M4952</guid>
      <dc:creator>khhenderson</dc:creator>
      <dc:date>2012-11-09T14:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk not indexing the entire file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-indexing-the-entire-file/m-p/28820#M4953</link>
      <description>&lt;P&gt;Double check and see that your events are not being timestamped incorrectly and they are not appearing elsewhere in your index.&lt;/P&gt;

&lt;P&gt;Does it still show only one event if you directly reference the source file over all time? ie. index=blah source=/opt/jrun4/logs/server-2-event.log&lt;/P&gt;</description>
      <pubDate>Sun, 11 Nov 2012 22:10:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-not-indexing-the-entire-file/m-p/28820#M4953</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2012-11-11T22:10:05Z</dc:date>
    </item>
  </channel>
</rss>

