<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ERROR TailReader - Was unable to open file /path/to/app/string-eventlogfile-splunk.csv in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TailReader-Was-unable-to-open-file-path-to-app-string/m-p/539242#M90340</link>
    <description>&lt;P&gt;Hi Splunk folks,&lt;BR /&gt;&lt;BR /&gt;I am getting the above errors with in&amp;nbsp; my _internals logs.&amp;nbsp;&lt;BR /&gt;nothing implies to me from this post&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Getting-Error-from-TailReader/m-p/356760" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Getting-Error-from-TailReader/m-p/356760&lt;/A&gt;&lt;BR /&gt;I have checked that file exits on host but UF is unable to read and send to indexers.&lt;BR /&gt;I have checked permissions, the header is same for all the file, and there are plenty of resources on the host and this is the only app running on the host where UF is running.&lt;BR /&gt;we have distributed deployment.&lt;BR /&gt;&lt;BR /&gt;here comes the weird part....we miss some data(files) for few days and then it works fine for few days... so when we find the files which are not being ingested to indexers from UF, we manually touch the file from backend(which change the time stamp) and then we get success. but there too many to touch and so time consuming.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[salesforce_csv_input]&lt;BR /&gt;TZ = GMT&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;TRUNCATE = 60000&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;CHECK_FOR_HEADER = true&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;category = Structured&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS....&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS...&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;inputs.conf&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;[monitor:///path/to/app/*-eventlogfile-splunk.csv]&lt;BR /&gt;index = salesforce&lt;BR /&gt;sourcetype = salesforce_csv_input&lt;BR /&gt;disabled = 0&lt;BR /&gt;initCrcLength = 1024&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Feb 2021 05:10:55 GMT</pubDate>
    <dc:creator>sanjum</dc:creator>
    <dc:date>2021-02-10T05:10:55Z</dc:date>
    <item>
      <title>ERROR TailReader - Was unable to open file /path/to/app/string-eventlogfile-splunk.csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TailReader-Was-unable-to-open-file-path-to-app-string/m-p/539242#M90340</link>
      <description>&lt;P&gt;Hi Splunk folks,&lt;BR /&gt;&lt;BR /&gt;I am getting the above errors with in&amp;nbsp; my _internals logs.&amp;nbsp;&lt;BR /&gt;nothing implies to me from this post&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Getting-Error-from-TailReader/m-p/356760" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Getting-Error-from-TailReader/m-p/356760&lt;/A&gt;&lt;BR /&gt;I have checked that file exits on host but UF is unable to read and send to indexers.&lt;BR /&gt;I have checked permissions, the header is same for all the file, and there are plenty of resources on the host and this is the only app running on the host where UF is running.&lt;BR /&gt;we have distributed deployment.&lt;BR /&gt;&lt;BR /&gt;here comes the weird part....we miss some data(files) for few days and then it works fine for few days... so when we find the files which are not being ingested to indexers from UF, we manually touch the file from backend(which change the time stamp) and then we get success. but there too many to touch and so time consuming.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[salesforce_csv_input]&lt;BR /&gt;TZ = GMT&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;TRUNCATE = 60000&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;INDEXED_EXTRACTIONS = csv&lt;BR /&gt;CHECK_FOR_HEADER = true&lt;BR /&gt;KV_MODE = none&lt;BR /&gt;category = Structured&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS....&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS.....&lt;BR /&gt;FIELDALIAS...&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;inputs.conf&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;[monitor:///path/to/app/*-eventlogfile-splunk.csv]&lt;BR /&gt;index = salesforce&lt;BR /&gt;sourcetype = salesforce_csv_input&lt;BR /&gt;disabled = 0&lt;BR /&gt;initCrcLength = 1024&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 05:10:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TailReader-Was-unable-to-open-file-path-to-app-string/m-p/539242#M90340</guid>
      <dc:creator>sanjum</dc:creator>
      <dc:date>2021-02-10T05:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TailReader - Was unable to open file /path/to/app/string-eventlogfile-splunk.csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ERROR-TailReader-Was-unable-to-open-file-path-to-app-string/m-p/540896#M90539</link>
      <description>&lt;P&gt;&lt;SPAN class="t"&gt;when we are missing data usually there is peak on warnings like this.&lt;BR /&gt;02-20-2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;01:59:49.493&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-0500&lt;/SPAN&gt; &lt;SPAN class="t"&gt;WARN&lt;/SPAN&gt; &lt;SPAN class="t"&gt;TcpOutputProc&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Cooked&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;connection&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ip=###########:9996&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timed&lt;/SPAN&gt; &lt;SPAN class="t"&gt;out&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 18:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ERROR-TailReader-Was-unable-to-open-file-path-to-app-string/m-p/540896#M90539</guid>
      <dc:creator>sanjum</dc:creator>
      <dc:date>2021-02-22T18:28:29Z</dc:date>
    </item>
  </channel>
</rss>

