<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Monitor File and Folder: Not uploading all files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392023#M70010</link>
    <description>&lt;P&gt;HI All,&lt;/P&gt;

&lt;P&gt;I am trying to monitor 3 CSVs from a same folder via Splunk : Settings -&amp;gt; Data Input -&amp;gt; Files &amp;amp; Directories.&lt;BR /&gt;
My Files are Alpha1.csv, Beta1.csv and Gamma1.csv. and the sourcetpyes are Alpha , Beta and Gamma with a proper timestamp (predefined). &lt;BR /&gt;
so in the  Settings -&amp;gt; Data Input -&amp;gt; Files &amp;amp; Directories: I added the files as:- &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Full path: C:\FileLOG\Alpha*.csv 
Whitelist:  Alpha
SourceType: Alpha
Index = Index1

Full path: C:\FileLOG\Beta*.csv 
Whitelist:  Beta
SourceType: Beta
Index = Index1

Full path: C:\FileLOG\Gamma*.csv 
Whitelist:  Gamma
SourceType: Gamma
Index = Index1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when I check Splunk, it shows me events only from C:\FileLOG\Gamma*.csv. Normal Upload of data is working fine and there is no issue with source type or index. Just the monitor function won't upload all files, although different rules are applied. &lt;/P&gt;

&lt;P&gt;thanks for the help and my apologies for such a long post. &lt;/P&gt;</description>
    <pubDate>Thu, 14 Jun 2018 10:45:23 GMT</pubDate>
    <dc:creator>Chandras11</dc:creator>
    <dc:date>2018-06-14T10:45:23Z</dc:date>
    <item>
      <title>Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392023#M70010</link>
      <description>&lt;P&gt;HI All,&lt;/P&gt;

&lt;P&gt;I am trying to monitor 3 CSVs from a same folder via Splunk : Settings -&amp;gt; Data Input -&amp;gt; Files &amp;amp; Directories.&lt;BR /&gt;
My Files are Alpha1.csv, Beta1.csv and Gamma1.csv. and the sourcetpyes are Alpha , Beta and Gamma with a proper timestamp (predefined). &lt;BR /&gt;
so in the  Settings -&amp;gt; Data Input -&amp;gt; Files &amp;amp; Directories: I added the files as:- &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Full path: C:\FileLOG\Alpha*.csv 
Whitelist:  Alpha
SourceType: Alpha
Index = Index1

Full path: C:\FileLOG\Beta*.csv 
Whitelist:  Beta
SourceType: Beta
Index = Index1

Full path: C:\FileLOG\Gamma*.csv 
Whitelist:  Gamma
SourceType: Gamma
Index = Index1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, when I check Splunk, it shows me events only from C:\FileLOG\Gamma*.csv. Normal Upload of data is working fine and there is no issue with source type or index. Just the monitor function won't upload all files, although different rules are applied. &lt;/P&gt;

&lt;P&gt;thanks for the help and my apologies for such a long post. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 10:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392023#M70010</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2018-06-14T10:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392024#M70011</link>
      <description>&lt;P&gt;Can you share  a screenshot of the relevant part of the Settings -&amp;gt; Data Input -&amp;gt; Files &amp;amp; Directories page, showing the entries for those 3 inputs? (or if you know how to find it: share the inputs.conf file that was generated for this).&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392024#M70011</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-14T11:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392025#M70012</link>
      <description>&lt;P&gt;I cannot share the screenshot from Splunk (Sensitive Data), but I can share entries in input.conf in&lt;BR /&gt;&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local &lt;BR /&gt;
    [default]&lt;BR /&gt;
    host = CPX-XXXXXXXX&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392025#M70012</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2018-06-14T11:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392026#M70013</link>
      <description>&lt;P&gt;check the results of this search for crcinit issues, permissions isssues, etc.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal log_level=warn* OR log_level=error
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392026#M70013</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-06-14T11:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392027#M70014</link>
      <description>&lt;P&gt;Thanks for it. I found the error as: &lt;/P&gt;

&lt;P&gt;06-14-2018 10:43:10.159 +0200 ERROR TailReader - File will not be read, is too small to match seekptr checksum (file=C:\FileLOG\Alpha1.csv).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;

&lt;P&gt;06-14-2018 10:43:10.079 +0200 ERROR TailReader - File will not be read, seekptr checksum did not match (file=C:\FileLOG\Beta1.csv ).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392027#M70014</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2018-06-14T11:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392028#M70015</link>
      <description>&lt;P&gt;Sounds like the first bits of those CSV files may be too similar. Increasing the initCrcLen or adding &lt;CODE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/CODE&gt; (literally like that) in the inputs.conf for each of those inputs might resolve your issue.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392028#M70015</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-14T11:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392029#M70016</link>
      <description>&lt;P&gt;That's not the relevant inputs.conf file. Not sure in which app the config was added, but you might want to take a look in etc/apps/search/local/inputs.conf&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:37:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392029#M70016</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-14T11:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392030#M70017</link>
      <description>&lt;P&gt;Thanks a lot for the comment.  Now my input.conf looks like:&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = CPX-XXXXXXXX&lt;BR /&gt;
crcSalt = &lt;/P&gt;

&lt;P&gt;Do I need to specify all files and add crcSalt for all of them? Sorry but the Splunk answer is removing the SOURCE keyword automatically &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:42:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392030#M70017</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2018-06-14T11:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392031#M70018</link>
      <description>&lt;P&gt;No, you need to find the inputs.conf file where the inputs are already configured (as mentioned in my other comment, my guess would be they are under etc/apps/search/local/). And then add the crcSalt setting there in each section for the three csv inputs.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392031#M70018</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-14T11:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392032#M70019</link>
      <description>&lt;P&gt;Sorry but there is no input.conf under etc/apps/search/local/. I found one under  Splunk\etc\system\local&lt;BR /&gt;&lt;BR /&gt;
but there is no different lines for different sourcetype. I believe I am not looking at the correct place. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392032#M70019</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2018-06-14T11:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392033#M70020</link>
      <description>&lt;P&gt;Have a look on the data inputs page that lists all the configured inputs. That should also mention in which app the config was stored. That should help you find it on the filesystem.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 12:04:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392033#M70020</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-14T12:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392034#M70021</link>
      <description>&lt;P&gt;Thanks a lot Frank. I got it with the command:  $ find . -name inputs.conf -print . It was udner the C:\Program Files\Splunk\etc\apps\MYAPP\local folder&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 12:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392034#M70021</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2018-06-14T12:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392035#M70022</link>
      <description>&lt;P&gt;So now you will have a stanza like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [monitor::/path/to/folder/*.log]
 crcSalt=&amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And that will fix the problem after restarting. &lt;/P&gt;

&lt;P&gt;You may have to clear the fish bucket or use another index name to get it to reload the data.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 22:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392035#M70022</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-06-14T22:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Monitor File and Folder: Not uploading all files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392036#M70023</link>
      <description>&lt;P&gt;So, if anyone gets the same issue, the workaround is:-&lt;BR /&gt;
First run the query in splunk search head:-&lt;BR /&gt;
index=_internal log_level=warn* OR log_level=error  and check for the time, when you put the CSVs in the folder. &lt;BR /&gt;
You will get the possible error or warning. I got the following:&lt;BR /&gt;
    06-14-2018 10:43:10.079 +0200 ERROR TailReader - File will not be read, seekptr checksum did not match (file=C:\FileLOG\Beta1.csv ). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;

&lt;P&gt;So I had the issue with crcSalt. Then I need to locate my correct input.conf and put an stanza similar to  [monitor::/path/to/folder/*.csv]&lt;BR /&gt;
  crcSalt= &lt;/P&gt;

&lt;P&gt;So locate the correct input.conf, you can use the command  $ find . -name inputs.conf -print... &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:00:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Monitor-File-and-Folder-Not-uploading-all-files/m-p/392036#M70023</guid>
      <dc:creator>Chandras11</dc:creator>
      <dc:date>2020-09-29T20:00:37Z</dc:date>
    </item>
  </channel>
</rss>

