<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with ERROR TailReader - File will not be read, is too small to match seekptr checksum in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Problem-with-ERROR-TailReader-File-will-not-be-read-is-too-small/m-p/550374#M91398</link>
    <description>&lt;P&gt;Hi there can someone please help.&amp;nbsp; &amp;nbsp;I am using the free trial version of Splunk Enterprise.&lt;BR /&gt;&lt;BR /&gt;I have set up a Data Input (Monitor) on a folder containing three files, one for each month, Jan, Feb and Mar.&amp;nbsp; Feb and Mar load without any problems however Jan fails to load with the following error entry in the log files:&lt;BR /&gt;&lt;BR /&gt;05-04-2021 12:17:37.361 +0100 ERROR TailReader - File will not be read, is too small to match seekptr checksum (file=C:\SplunkData\PI\POC_PI_Data_Jan.csv). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;&lt;P&gt;I have tried deleteing the Data Input and related Index, recreating from scratch, without any luck.&amp;nbsp; I then deleted the content a second time, restarted the splunkd Windows Service, and created everything from scratch a third time, but just get the same error.&amp;nbsp; There does not appeat to be anything wrong with the CSV file, which is&amp;nbsp;916,686 rows long with 4 fields, (Tag, TimeStamp, Value, Status).&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;BR /&gt;Paul J.&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 11:38:26 GMT</pubDate>
    <dc:creator>pjAstroMan</dc:creator>
    <dc:date>2021-05-04T11:38:26Z</dc:date>
    <item>
      <title>Problem with ERROR TailReader - File will not be read, is too small to match seekptr checksum</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Problem-with-ERROR-TailReader-File-will-not-be-read-is-too-small/m-p/550374#M91398</link>
      <description>&lt;P&gt;Hi there can someone please help.&amp;nbsp; &amp;nbsp;I am using the free trial version of Splunk Enterprise.&lt;BR /&gt;&lt;BR /&gt;I have set up a Data Input (Monitor) on a folder containing three files, one for each month, Jan, Feb and Mar.&amp;nbsp; Feb and Mar load without any problems however Jan fails to load with the following error entry in the log files:&lt;BR /&gt;&lt;BR /&gt;05-04-2021 12:17:37.361 +0100 ERROR TailReader - File will not be read, is too small to match seekptr checksum (file=C:\SplunkData\PI\POC_PI_Data_Jan.csv). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;&lt;P&gt;I have tried deleteing the Data Input and related Index, recreating from scratch, without any luck.&amp;nbsp; I then deleted the content a second time, restarted the splunkd Windows Service, and created everything from scratch a third time, but just get the same error.&amp;nbsp; There does not appeat to be anything wrong with the CSV file, which is&amp;nbsp;916,686 rows long with 4 fields, (Tag, TimeStamp, Value, Status).&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;BR /&gt;Paul J.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 11:38:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Problem-with-ERROR-TailReader-File-will-not-be-read-is-too-small/m-p/550374#M91398</guid>
      <dc:creator>pjAstroMan</dc:creator>
      <dc:date>2021-05-04T11:38:26Z</dc:date>
    </item>
  </channel>
</rss>

