<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk stopped indexing file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51346#M9846</link>
    <description>&lt;P&gt;After upgrading a Solaris SPARC forwarder from Splunk 3.4.9 to 4.1.4 (build 82143) one log file stopped being indexed. Lots of new data is being written to it, but I'm not seeing it on the indexer. Ten plus other files are being monitored fine from the same forwarder. In inputs.conf it's:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///log/syslog/network/netscalar.log]
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the TailingProcessor:FileStatus it's:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;log/syslog/network/netscalar.log    
file position   10184387
file size   10184387
percent 100.00
type    open file
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The log file is rotated, so there is also netscalar.log.1 and so on in the directory. I tried clearing the eventdata in the fishbucket, which took a few hours but it read all the files again, but that didn't fix it. Is there a way I can get Splunk to treat this file as entirely new to get this data indexed?&lt;/P&gt;</description>
    <pubDate>Mon, 14 May 2012 16:15:43 GMT</pubDate>
    <dc:creator>kaufmanm</dc:creator>
    <dc:date>2012-05-14T16:15:43Z</dc:date>
    <item>
      <title>Splunk stopped indexing file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51346#M9846</link>
      <description>&lt;P&gt;After upgrading a Solaris SPARC forwarder from Splunk 3.4.9 to 4.1.4 (build 82143) one log file stopped being indexed. Lots of new data is being written to it, but I'm not seeing it on the indexer. Ten plus other files are being monitored fine from the same forwarder. In inputs.conf it's:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///log/syslog/network/netscalar.log]
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the TailingProcessor:FileStatus it's:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;log/syslog/network/netscalar.log    
file position   10184387
file size   10184387
percent 100.00
type    open file
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The log file is rotated, so there is also netscalar.log.1 and so on in the directory. I tried clearing the eventdata in the fishbucket, which took a few hours but it read all the files again, but that didn't fix it. Is there a way I can get Splunk to treat this file as entirely new to get this data indexed?&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 16:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51346#M9846</guid>
      <dc:creator>kaufmanm</dc:creator>
      <dc:date>2012-05-14T16:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stopped indexing file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51347#M9847</link>
      <description>&lt;P&gt;I've seen issues in the past where a file stops forwarding because of the rotation strategy - whether the file is moved (inode change) or copied and truncated in place. Not sure if that's still an issue with the newest versions of splunk, but we used to handle this situation by splunking the directory and then whitelisting for the specific file.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 18:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51347#M9847</guid>
      <dc:creator>briang67</dc:creator>
      <dc:date>2012-05-14T18:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stopped indexing file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51348#M9848</link>
      <description>&lt;P&gt;I changed inputs.conf to monitor the directory and _whitelist the file, but it still shows up as 100% read in the TailingProcessor:FileStatus. FWIW, the file size there is the same as the actual file size on the disk.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 18:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51348#M9848</guid>
      <dc:creator>kaufmanm</dc:creator>
      <dc:date>2012-05-14T18:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk stopped indexing file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51349#M9849</link>
      <description>&lt;P&gt;I deleted the log file and created a new one and Splunk is indexing it fine, thanks all set.&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2012 13:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-stopped-indexing-file/m-p/51349#M9849</guid>
      <dc:creator>kaufmanm</dc:creator>
      <dc:date>2012-05-15T13:38:59Z</dc:date>
    </item>
  </channel>
</rss>

