<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder- seekptr checksum error and logs not being sent in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-seekptr-checksum-error-and-logs-not-being-sent/m-p/515884#M87344</link>
    <description>&lt;P&gt;Moved question to Splunk Adminstration, "Getting Data In", where you will get better answers than in "Search".&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Aug 2020 20:11:56 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2020-08-24T20:11:56Z</dc:date>
    <item>
      <title>Forwarder- seekptr checksum error and logs not being sent</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-seekptr-checksum-error-and-logs-not-being-sent/m-p/515870#M87343</link>
      <description>&lt;P&gt;While debugging an issue where a forwarder would not send a specific log to our main splunk instance,&amp;nbsp; i found this great post (among others):&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Unix-Forwarder-is-not-Sending-Logs/m-p/167347/highlight/true#M6237" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Unix-Forwarder-is-not-Sending-Logs/m-p/167347/highlight/true#M6237&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in the inputs.conf on the Universal Forwarder, &lt;STRONG&gt;the fix was adding initCrcLength = 2048&lt;/STRONG&gt;&amp;nbsp; to the specific logs stanza:&lt;/P&gt;&lt;P&gt;( in:&amp;nbsp; C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf)&lt;/P&gt;&lt;P&gt;Apparently the default is&amp;nbsp;&lt;SPAN&gt;initCrcLength = 256.&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;This made me start thinking,&amp;nbsp; how many other forwarder logs are we not getting/indexing that im not aware of !?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thus,&amp;nbsp; this search below showed me that 4 of our Forwarder's&amp;nbsp;(of ~22 forwarders&amp;nbsp;in total) where showing this same error for various specific log files (thus those specific logs have not been getting indexed):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal source=*splunkd.log host=* "seekptr checksum"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(while this is very unfortunate),&amp;nbsp; &lt;U&gt;my question is:&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Should we be manually setting something like&amp;nbsp;&lt;STRONG&gt;initCrcLength = 2048&amp;nbsp;&lt;/STRONG&gt;on every one of our Forwarders (and on future new&amp;nbsp;forwarders)?&lt;/U&gt;&lt;/P&gt;&lt;P&gt;I assume the downside is increased RAM and CPU usage on the forwarders (but this is not an issue for us, as volume is not very high, and resources plentiful).&amp;nbsp; Anything else im not considering as a downside?&lt;/P&gt;&lt;P&gt;&lt;U&gt;question 2:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I assume we can "globally" set this on a forwarders inputs.conf by simply placing:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[default]
initCrcLength = 2048&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and it will apply to all stanzas (unless a stanza overrides&amp;nbsp;initCrcLength, of-course), &lt;STRONG&gt;Right?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 19:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-seekptr-checksum-error-and-logs-not-being-sent/m-p/515870#M87343</guid>
      <dc:creator>spunk311z</dc:creator>
      <dc:date>2020-08-24T19:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder- seekptr checksum error and logs not being sent</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-seekptr-checksum-error-and-logs-not-being-sent/m-p/515884#M87344</link>
      <description>&lt;P&gt;Moved question to Splunk Adminstration, "Getting Data In", where you will get better answers than in "Search".&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 20:11:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-seekptr-checksum-error-and-logs-not-being-sent/m-p/515884#M87344</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-08-24T20:11:56Z</dc:date>
    </item>
  </channel>
</rss>

