<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to properly disable a WatchedFile using the Universal Forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346567#M63641</link>
    <description>&lt;P&gt;Do you install unix app?&lt;/P&gt;

&lt;P&gt;I get same information&lt;/P&gt;

&lt;P&gt;01-11-2018 16:36:05.204 +0800 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/etc/dfs/sharetab'. &lt;BR /&gt;
01-11-2018 16:36:06.266 +0800 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/etc/dfs/sharetab'. &lt;/P&gt;

&lt;P&gt;I found the app inputs.conf&lt;/P&gt;

&lt;P&gt;[monitor:///etc]&lt;BR /&gt;
_whitelist=(.conf|.cfg|config$|.ini|.init|.cf|.cnf|shrc$|^ifcfg|.profile|.rc|.rules|.tab|tab$|.login|policy$)&lt;BR /&gt;
&lt;STRONG&gt;blacklist = etc/dfs/&lt;/STRONG&gt;*&lt;BR /&gt;
index=os&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;The message won't be happened.&lt;/P&gt;

&lt;P&gt;It's useful for me. maybe you can try it.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2018 02:56:48 GMT</pubDate>
    <dc:creator>morgan03</dc:creator>
    <dc:date>2018-01-12T02:56:48Z</dc:date>
    <item>
      <title>How to properly disable a WatchedFile using the Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346566#M63640</link>
      <description>&lt;P&gt;On Solaris 10/11 - Our $SPLUNK_HOME/var/log/splunk/splunkd.log  file has many of the following messages, 1 per second every minute.&lt;/P&gt;

&lt;P&gt;08-02-2017 18:04:06.787 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/etc/dfs/sharetab'.&lt;/P&gt;

&lt;P&gt;I have tried various configs with the $SPLUNK_HOME/etc/system/local/inputs.conf    [blacklist:///etc/dfs/]  and [monitor://] with disable = true, but nothing works.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 23:21:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346566#M63640</guid>
      <dc:creator>thabben</dc:creator>
      <dc:date>2017-08-02T23:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable a WatchedFile using the Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346567#M63641</link>
      <description>&lt;P&gt;Do you install unix app?&lt;/P&gt;

&lt;P&gt;I get same information&lt;/P&gt;

&lt;P&gt;01-11-2018 16:36:05.204 +0800 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/etc/dfs/sharetab'. &lt;BR /&gt;
01-11-2018 16:36:06.266 +0800 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/etc/dfs/sharetab'. &lt;/P&gt;

&lt;P&gt;I found the app inputs.conf&lt;/P&gt;

&lt;P&gt;[monitor:///etc]&lt;BR /&gt;
_whitelist=(.conf|.cfg|config$|.ini|.init|.cf|.cnf|shrc$|^ifcfg|.profile|.rc|.rules|.tab|tab$|.login|policy$)&lt;BR /&gt;
&lt;STRONG&gt;blacklist = etc/dfs/&lt;/STRONG&gt;*&lt;BR /&gt;
index=os&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;The message won't be happened.&lt;/P&gt;

&lt;P&gt;It's useful for me. maybe you can try it.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 02:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346567#M63641</guid>
      <dc:creator>morgan03</dc:creator>
      <dc:date>2018-01-12T02:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly disable a WatchedFile using the Universal Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346568#M63642</link>
      <description>&lt;P&gt;You can determine which &lt;CODE&gt;monitor&lt;/CODE&gt; stanza is responsible for this by examining the output of:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk list monitor
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;After which you can work to tune your blacklist/whitelist to try to prevent it from being indexed.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2018 05:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-properly-disable-a-WatchedFile-using-the-Universal/m-p/346568#M63642</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-13T05:55:13Z</dc:date>
    </item>
  </channel>
</rss>

