<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What more can I do to solve: File too small to check seekcrc, probably truncated.  Will re-read entire file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185453#M98406</link>
    <description>&lt;P&gt;It has been a while since I did ask this question, and I realize that I most certainly did solve it when applying timestamp recogniction as described here &lt;A href="http://answers.splunk.com/answers/147950/can-i-have-different-timestamp-formats-using-the-same-sourcetype.html"&gt;http://answers.splunk.com/answers/147950/can-i-have-different-timestamp-formats-using-the-same-sourcetype.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Oct 2014 11:06:24 GMT</pubDate>
    <dc:creator>rune_hellem</dc:creator>
    <dc:date>2014-10-06T11:06:24Z</dc:date>
    <item>
      <title>What more can I do to solve: File too small to check seekcrc, probably truncated.  Will re-read entire file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185452#M98405</link>
      <description>&lt;P&gt;Running Splunk 6.0.1 (build 189883), all on Windows-servers, a mix of 2008/2012-servers.&lt;/P&gt;

&lt;P&gt;Indexing a lot of SystemOut.log-files from WebSphere, in most cases no problem at all, all events are showing fine, but some of the files are troublesome. For the file mentioned here it is being indexed on and off. Checking now the file was not indexed (or it was indexed, but only the startup-event being logged by WebSphere in that period) until Feb 17'th, then all fine until March the 9'th, and after that nothing, or again to be all precise: Only the startup event of WebSphere every time the JVM is restarted, no other events.&lt;/P&gt;

&lt;P&gt;From input.confs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://E:\logs\*Member*\SystemOut.log]
index = klpi
sourcetype = websphere:system:out
crcSalt = &amp;lt;SOURCE&amp;gt;
initCrcLength = 3000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk finds the file without problems&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="E:\\logs\\FondssparingAdminMember01\\SystemOut.log"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Checking the _internal-index there are no other events for that file than the "File to small...".&lt;/P&gt;

&lt;P&gt;WebSphere does rotate the log files when they reach 10Mb, but the date of when the file was rotated does not match the date when Splunk did start/stop receiving events (again - events other than the Startup-message)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 06:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185452#M98405</guid>
      <dc:creator>rune_hellem</dc:creator>
      <dc:date>2014-03-13T06:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: What more can I do to solve: File too small to check seekcrc, probably truncated.  Will re-read entire file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185453#M98406</link>
      <description>&lt;P&gt;It has been a while since I did ask this question, and I realize that I most certainly did solve it when applying timestamp recogniction as described here &lt;A href="http://answers.splunk.com/answers/147950/can-i-have-different-timestamp-formats-using-the-same-sourcetype.html"&gt;http://answers.splunk.com/answers/147950/can-i-have-different-timestamp-formats-using-the-same-sourcetype.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2014 11:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185453#M98406</guid>
      <dc:creator>rune_hellem</dc:creator>
      <dc:date>2014-10-06T11:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: What more can I do to solve: File too small to check seekcrc, probably truncated.  Will re-read entire file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185454#M98407</link>
      <description>&lt;P&gt;Was the CRC/re-reading issues caused by multiple timestamps in the file? Any idea why that would break things, and do you have any resources to splunk mentioning this? &lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 20:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-more-can-I-do-to-solve-File-too-small-to-check-seekcrc/m-p/185454#M98407</guid>
      <dc:creator>ljdelight</dc:creator>
      <dc:date>2017-06-14T20:47:17Z</dc:date>
    </item>
  </channel>
</rss>

