<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitor csv files directory Tail Reader Problem in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/526696#M88832</link>
    <description>&lt;P&gt;I am monitoring a directory with 101 csv file with the same format but I am having only 49 of them indexed.&amp;nbsp; When I start up the splunk I get warn message from TailReader - Could not send data to output queue (parsingqueue), retrying....&lt;/P&gt;&lt;P&gt;Sample of csv files:&lt;/P&gt;&lt;P&gt;Timestamp,Value (%)&lt;BR /&gt;21-Sep-20 6:38:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:39:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:40:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:41:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:42:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:43:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:44:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:45:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:46:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:47:01 AM BRT,0.0&lt;/P&gt;&lt;P&gt;Timestamp,Value (%)&lt;BR /&gt;21-Sep-20 6:38:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:39:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:40:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:41:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:42:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:43:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:44:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:45:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:46:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:47:01 AM BRT,0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[porto_file_csv]&lt;BR /&gt;BREAK_ONLY_BEFORE_DATE =&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;HEADER_FIELD_LINE_NUMBER = 13&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Structured&lt;BR /&gt;description = Comma-separated value format. Set header and other settings in "Delimited Settings"&lt;BR /&gt;disabled = false&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;EXTRACT-Chiller,Variavel = /opt/POC_Chiller/POC_(?P&amp;lt;Chiller&amp;gt;CH\d)_(?P&amp;lt;Variavel&amp;gt;\w+) in source&lt;BR /&gt;REPORT-poc_porto = REPORT-poc_porto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///opt/POC_Chiller]&lt;BR /&gt;disabled = false&lt;BR /&gt;host = test4&lt;BR /&gt;index = test_porto&lt;BR /&gt;sourcetype = porto_file_csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: I also have tried to monitor the files with default csv sourcetype and again it didn't work.&lt;/P&gt;&lt;P&gt;Any help, would very appreciated!&lt;/P&gt;&lt;P&gt;Marcos Pereira&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Oct 2020 18:56:36 GMT</pubDate>
    <dc:creator>marcos_eng1</dc:creator>
    <dc:date>2020-10-27T18:56:36Z</dc:date>
    <item>
      <title>Monitor csv files directory Tail Reader Problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/526696#M88832</link>
      <description>&lt;P&gt;I am monitoring a directory with 101 csv file with the same format but I am having only 49 of them indexed.&amp;nbsp; When I start up the splunk I get warn message from TailReader - Could not send data to output queue (parsingqueue), retrying....&lt;/P&gt;&lt;P&gt;Sample of csv files:&lt;/P&gt;&lt;P&gt;Timestamp,Value (%)&lt;BR /&gt;21-Sep-20 6:38:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:39:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:40:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:41:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:42:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:43:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:44:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:45:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:46:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:47:01 AM BRT,0.0&lt;/P&gt;&lt;P&gt;Timestamp,Value (%)&lt;BR /&gt;21-Sep-20 6:38:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:39:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:40:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:41:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:42:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:43:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:44:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:45:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:46:00 AM BRT,0.0&lt;BR /&gt;21-Sep-20 6:47:01 AM BRT,0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[porto_file_csv]&lt;BR /&gt;BREAK_ONLY_BEFORE_DATE =&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;HEADER_FIELD_LINE_NUMBER = 13&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;category = Structured&lt;BR /&gt;description = Comma-separated value format. Set header and other settings in "Delimited Settings"&lt;BR /&gt;disabled = false&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;EXTRACT-Chiller,Variavel = /opt/POC_Chiller/POC_(?P&amp;lt;Chiller&amp;gt;CH\d)_(?P&amp;lt;Variavel&amp;gt;\w+) in source&lt;BR /&gt;REPORT-poc_porto = REPORT-poc_porto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///opt/POC_Chiller]&lt;BR /&gt;disabled = false&lt;BR /&gt;host = test4&lt;BR /&gt;index = test_porto&lt;BR /&gt;sourcetype = porto_file_csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: I also have tried to monitor the files with default csv sourcetype and again it didn't work.&lt;/P&gt;&lt;P&gt;Any help, would very appreciated!&lt;/P&gt;&lt;P&gt;Marcos Pereira&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 18:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/526696#M88832</guid>
      <dc:creator>marcos_eng1</dc:creator>
      <dc:date>2020-10-27T18:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor csv files directory Tail Reader Problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/526707#M88836</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214240"&gt;@marcos_eng1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using an Universal Forwarder or a Heavy Forwarder instance for monitoring this csv files? Or the input stanza is on another instance?&lt;/P&gt;&lt;P&gt;Also, what is the size of these files?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 19:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/526707#M88836</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-10-27T19:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor csv files directory Tail Reader Problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527111#M88911</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using the inputs.conf in a standalone server.&lt;/P&gt;&lt;P&gt;Please, see my internal logs related the tailreader fail:&lt;/P&gt;&lt;P&gt;10-27-2020 16:02:40.320 -0300 ERROR TailReader - File will not be read, seekptr checksum did not match (file=/opt/POC_Chiller/POC_CH1_CAP_TOTAL_B.csv). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;10-27-2020 15:03:14.788 -0300 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/POC_Chiller/POC_CH1_CAP_TOTAL_B.csv'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527111#M88911</guid>
      <dc:creator>marcos_eng1</dc:creator>
      <dc:date>2020-10-29T15:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor csv files directory Tail Reader Problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527112#M88912</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also the csv files are not bigger than 17KB&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527112#M88912</guid>
      <dc:creator>marcos_eng1</dc:creator>
      <dc:date>2020-10-29T15:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor csv files directory Tail Reader Problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527124#M88914</link>
      <description>&lt;P&gt;Are you generating new files with the same name? Or just updating Its content?&lt;/P&gt;&lt;P&gt;Looking at the error on the internal log you provided, I would try testing the crcSalt option on your monitoring input stanza (If file name keeps changing and all new files are created with a different name).&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;If you create files using the same file name (replacing them, instead of updating), I would try increasing the&amp;nbsp;&lt;SPAN&gt;initCrcLength option. The default value is 256&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;initCrcLength = &amp;lt;INTEGER&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;Both options are from inputs.conf. Also, If you need, refer to this doc to get more information about the two mentioned options:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:45:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527124#M88914</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-10-29T15:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor csv files directory Tail Reader Problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527138#M88915</link>
      <description>&lt;P&gt;I worked.....Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 16:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-csv-files-directory-Tail-Reader-Problem/m-p/527138#M88915</guid>
      <dc:creator>marcos_eng1</dc:creator>
      <dc:date>2020-10-29T16:46:29Z</dc:date>
    </item>
  </channel>
</rss>

