<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with monitoring one specific log file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397792#M70928</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am monitoring multiple files/directory under different sourcetype.  For one specific log file I am getting wiered behavior. &lt;BR /&gt;
It's not being monitored Continuously, even though file is getting updated regularly.&lt;/P&gt;

&lt;P&gt;I am not getting any relevant error at both Splunk and forwarder side.&lt;/P&gt;

&lt;P&gt;Whenever I install new forwarder and configure this file to read, file is being picked only once and stop updating . (It's like reading a batch file)&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///net/hp707srv/hp707srv2/apps/QCST_RSAT_v3.1.42_MASTER/qcstTools/qcst_out_alerts.log]
disabled = false
host = MTE_TEST
index = mlc_live
sourcetype = MTE_ALERT
crcSalt = &amp;lt;Source&amp;gt; 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 03 Apr 2019 12:50:28 GMT</pubDate>
    <dc:creator>AKG1_old1</dc:creator>
    <dc:date>2019-04-03T12:50:28Z</dc:date>
    <item>
      <title>Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397792#M70928</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am monitoring multiple files/directory under different sourcetype.  For one specific log file I am getting wiered behavior. &lt;BR /&gt;
It's not being monitored Continuously, even though file is getting updated regularly.&lt;/P&gt;

&lt;P&gt;I am not getting any relevant error at both Splunk and forwarder side.&lt;/P&gt;

&lt;P&gt;Whenever I install new forwarder and configure this file to read, file is being picked only once and stop updating . (It's like reading a batch file)&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///net/hp707srv/hp707srv2/apps/QCST_RSAT_v3.1.42_MASTER/qcstTools/qcst_out_alerts.log]
disabled = false
host = MTE_TEST
index = mlc_live
sourcetype = MTE_ALERT
crcSalt = &amp;lt;Source&amp;gt; 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Apr 2019 12:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397792#M70928</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2019-04-03T12:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397793#M70929</link>
      <description>&lt;P&gt;Have you considered &lt;STRONG&gt;crcSalt&lt;/STRONG&gt; as described in &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 13:43:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397793#M70929</guid>
      <dc:creator>Laszlo_K</dc:creator>
      <dc:date>2019-04-03T13:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397794#M70930</link>
      <description>&lt;P&gt;When you define monitor stanza (the others in your inputs.conf in the UF/HF), are you ensuring that no other stanza is resolving to the above path &lt;CODE&gt;///net/hp707srv/hp707srv2/apps/QCST_RSAT_v3.1.42_MASTER/qcstTools/&lt;/CODE&gt; ?   &lt;/P&gt;

&lt;P&gt;Also, how often does this file get updated and rotated? did you try crcSalt /crc checksum length?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 15:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397794#M70930</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-04-03T15:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397795#M70931</link>
      <description>&lt;P&gt;I have tried installing fresh forwarder for monitoring only this file. After starting the forwarder full file injested in Splunk but later on it's not getting updated.&lt;/P&gt;

&lt;P&gt;I have used crcSalt =  as well but didn't work. &lt;/P&gt;

&lt;P&gt;Around 30-50 lines are updated in one hour.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 15:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397795#M70931</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2019-04-03T15:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397796#M70932</link>
      <description>&lt;P&gt;yesI have tried with&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; crcSalt = &amp;lt;Source&amp;gt; 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 Apr 2019 16:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397796#M70932</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2019-04-03T16:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397797#M70933</link>
      <description>&lt;P&gt;Assuming, you get new events every 1hr, are you seeing any warning/errors in splunkd.log from the time your file is first indexed to say till next 1 or 2 hrs? [ e.g file crc checksum error, file ignored, parsing error]. Also, using the metrics.log, can you check if you are constantly receiving other _internal logs from the host, so we can isolate the issue to only this specific file. I assume this is a normal text file.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 04:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397797#M70933</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-04-04T04:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397798#M70934</link>
      <description>&lt;P&gt;Issue is resolved by updating TIME_FORMAT In props.conf&lt;BR /&gt;
Earlier TIME_FORMAT  was not defined. but wiered thing is it was working fine initially for a month with no TIME_FORMAT . My assumption is if its not defined it takes current time bydefault. &lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
    [MTE_ALERT]&lt;BR /&gt;
    DATETIME_CONFIG = &lt;BR /&gt;
    NO_BINARY_CHECK = true&lt;BR /&gt;
    SHOULD_LINEMERGE = false&lt;BR /&gt;
    category = Custom&lt;BR /&gt;
    disabled = false&lt;BR /&gt;
    pulldown_type = true&lt;BR /&gt;
    REPORT-MTE_ALERT = REPORT-MTE_ALERT&lt;BR /&gt;
    TIME_FORMAT = %d/%m/%Y | %H:%M:%S&lt;BR /&gt;
    TIME_PREFIX = ^&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397798#M70934</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2020-09-30T00:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring one specific log file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397799#M70935</link>
      <description>&lt;P&gt;@lakshman239 : Thanks for help. its got resovled.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 08:40:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-one-specific-log-file/m-p/397799#M70935</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2019-04-04T08:40:31Z</dc:date>
    </item>
  </channel>
</rss>

