<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why can't the forwarder index and populate data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335294#M62011</link>
    <description>&lt;P&gt;Hello shawno,&lt;/P&gt;

&lt;P&gt;Bunch of messages are happening from  your posted splunkd.log.&lt;BR /&gt;
You might want to address some of them if they're part of your requirement too.&lt;BR /&gt;
Most of the messages are straightforward and can addressed individually.&lt;/P&gt;

&lt;P&gt;For example, /tmp/hsperfdata_root/3843 is being ignored due to binary.&lt;BR /&gt;
Check this h&lt;A href="http://ttps://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Propsconf#Binary_file_configuration" target="_blank"&gt;ttps://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Propsconf#Binary_file_configuration&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 18:20:41 GMT</pubDate>
    <dc:creator>lloydknight</dc:creator>
    <dc:date>2020-09-29T18:20:41Z</dc:date>
    <item>
      <title>Why can't the forwarder index and populate data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335292#M62009</link>
      <description>&lt;P&gt;We're unable to get the forwarder to index/re-index and populate data - any make out what is happening here?  Thanks&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-06-2018 22:08:21.280 +0000 INFO  TailReader - Ignoring file '/tmp/hsperfdata_root/3843' due to: binary
03-06-2018 22:08:39.078 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh" which: no tshark in (/opt/splunk/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/root/bin)
03-06-2018 22:08:39.104 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh" /opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh: line 8: -v: command not found
03-06-2018 22:08:39.111 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh" /opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh: line 31: [: : integer expression expected
03-06-2018 22:08:39.153 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_nix/bin/rlog.sh" Redirecting to /bin/systemctl status auditd.service
03-06-2018 22:08:40.347 +0000 WARN  FileClassifierManager - The file '/tmp/hsperfdata_root/3843' is invalid. Reason: binary
03-06-2018 22:08:40.347 +0000 INFO  TailReader - Ignoring file '/tmp/hsperfdata_root/3843' due to: binary
03-06-2018 22:08:48.320 +0000 WARN  LineBreakingProcessor - Truncating line because limit of 1000000 bytes has been exceeded with a line length &amp;gt;= 1003520 - data_source="lsof", data_host="harplg01.stag.defence.gov.au", data_sourcetype="lsof"
03-06-2018 22:09:08.887 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh" which: no tshark in (/opt/splunk/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/root/bin)
03-06-2018 22:09:08.936 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh" /opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh: line 8: -v: command not found
03-06-2018 22:09:08.947 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh" /opt/splunk/etc/apps/SplunkForPCAP/bin/pcap2csv.sh: line 31: [: : integer expression expected
03-06-2018 22:09:10.449 +0000 WARN  FileClassifierManager - The file '/tmp/hsperfdata_root/3843' is invalid. Reason: binary
03-06-2018 22:09:10.449 +0000 INFO  TailReader - Ignoring file '/tmp/hsperfdata_root/3843' due to: binary
03-06-2018 22:09:19.336 +0000 WARN  DateParserVerbose - Accepted time format has changed ((?i)(?
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 08 Mar 2018 01:07:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335292#M62009</guid>
      <dc:creator>shawno</dc:creator>
      <dc:date>2018-03-08T01:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the forwarder index and populate data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335293#M62010</link>
      <description>&lt;P&gt;Hello @shawno&lt;/P&gt;

&lt;P&gt;Kindly check this similar question below:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html"&gt;https://answers.splunk.com/answers/72562/how-to-reindex-data-from-a-forwarder.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 02:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335293#M62010</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2018-03-08T02:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the forwarder index and populate data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335294#M62011</link>
      <description>&lt;P&gt;Hello shawno,&lt;/P&gt;

&lt;P&gt;Bunch of messages are happening from  your posted splunkd.log.&lt;BR /&gt;
You might want to address some of them if they're part of your requirement too.&lt;BR /&gt;
Most of the messages are straightforward and can addressed individually.&lt;/P&gt;

&lt;P&gt;For example, /tmp/hsperfdata_root/3843 is being ignored due to binary.&lt;BR /&gt;
Check this h&lt;A href="http://ttps://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Propsconf#Binary_file_configuration" target="_blank"&gt;ttps://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Propsconf#Binary_file_configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:20:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335294#M62011</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2020-09-29T18:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't the forwarder index and populate data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335295#M62012</link>
      <description>&lt;P&gt;I've already used this article and no joy...  &lt;/P&gt;

&lt;P&gt;02-12-2018 02:43:58.919 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;BR /&gt;
02-12-2018 02:43:58.951 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/btool.log'.&lt;BR /&gt;
02-12-2018 02:43:58.975 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/searchhistory.log'.&lt;BR /&gt;
02-12-2018 02:43:58.984 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_access.log'.&lt;BR /&gt;
02-12-2018 02:43:59.005 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/license_usage.log'.&lt;BR /&gt;
02-12-2018 02:43:59.023 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/license_audit.log'.&lt;BR /&gt;
02-12-2018 02:43:59.049 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/remote_searches.log'.&lt;BR /&gt;
02-12-2018 02:43:59.058 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/scheduler.log'.&lt;BR /&gt;
02-12-2018 02:43:59.067 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_stdout.log'.&lt;BR /&gt;
02-12-2018 02:44:09.087 +0000 INFO  DC:HandshakeReplyHandler - Handshake done.&lt;BR /&gt;
02-12-2018 03:01:12.814 +0000 INFO  DeployedApplication - Checksum mismatch 0 &amp;lt;&amp;gt; 594566478266413569 for app=_server_app_bluecoat. Will reload from='10.27.22.218:8089/services/streams/deployment?name=default:bluecoat_ftp:_server_app_bluec&lt;BR /&gt;
oat'&lt;BR /&gt;
02-12-2018 03:01:12.896 +0000 INFO  DeployedApplication - Downloaded url=10.27.22.218:8089/services/streams/deployment?name=default:bluecoat_ftp:_server_app_bluecoat to file='/opt/splunkforwarder/var/run/bluecoat_ftp/_server_app_bluecoat&lt;BR /&gt;
-1518404458.bundle' sizeKB=10&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:20:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-the-forwarder-index-and-populate-data/m-p/335295#M62012</guid>
      <dc:creator>shawno</dc:creator>
      <dc:date>2020-09-29T18:20:44Z</dc:date>
    </item>
  </channel>
</rss>

