<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows DHCP Server (2003) in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26662#M9213</link>
    <description>&lt;P&gt;Can you include the monitor stanza you are using?  My guess is you need to specify &lt;CODE&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/CODE&gt;, but I can't be sure without more information.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Nov 2012 15:34:33 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2012-11-08T15:34:33Z</dc:date>
    <item>
      <title>Windows DHCP Server (2003)</title>
      <link>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26661#M9212</link>
      <description>&lt;P&gt;We are monitoring Windows 2003 DHCP service from c:\windows\system32\dhcp and there are 7 log files, one for each day.&lt;/P&gt;

&lt;P&gt;DhcpSrvLog-Mon.log&lt;BR /&gt;
DhcpSrvLog-Tue.log&lt;BR /&gt;
...and so on&lt;/P&gt;

&lt;P&gt;At the end of the Monday, the log file closes and then logging starts anew in the Tuesday log file.  For some reason, Splunk is not picking up this 'change' in the log file and does not log the Tuesday file until Splunk is restarted.  I can simply restart the Splunkforwarder service every night at 12am but I'm wondering if I'm missing a configuration item.&lt;/P&gt;

&lt;P&gt;Thanks, Mike&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 17:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26661#M9212</guid>
      <dc:creator>mdavis43</dc:creator>
      <dc:date>2012-11-07T17:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DHCP Server (2003)</title>
      <link>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26662#M9213</link>
      <description>&lt;P&gt;Can you include the monitor stanza you are using?  My guess is you need to specify &lt;CODE&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/CODE&gt;, but I can't be sure without more information.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 15:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26662#M9213</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-11-08T15:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DHCP Server (2003)</title>
      <link>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26663#M9214</link>
      <description>&lt;P&gt;Here is the monitor stanza...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://C:\Windows\system32\dhcp\Dhcp*.log]
disabled = false
index = win_prod
sourcetype=DhcpSrvLog
blacklist = \.(gz|bz2|z|zip)$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 08 Nov 2012 17:29:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26663#M9214</guid>
      <dc:creator>mdavis43</dc:creator>
      <dc:date>2012-11-08T17:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows DHCP Server (2003)</title>
      <link>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26664#M9215</link>
      <description>&lt;P&gt;Splunk Support answered this..&lt;/P&gt;

&lt;P&gt;I agree that there's little reason to use a forwarder restart to manage the ingestion of Windows DHCP logs. In Splunk version 5, the inputs.conf parameter 'initcrclength' was added and certainly could be utilized once you're running on that version.&lt;BR /&gt;
As you're on 4.3.x the best way to manage the DHCP logs is documented here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/1568/windows-dhcp-log-files-too-small-to-match-seekptr-checksum"&gt;http://splunk-base.splunk.com/answers/1568/windows-dhcp-log-files-too-small-to-match-seekptr-checksum&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Paying particular attention to the example monitor stanza with the whitelist entry and crcsalt:&lt;/P&gt;

&lt;P&gt;whitelist = DhcpSrvLog.(Sun|Mon|Tue|Wed|Thu|Fri|Sat)$&lt;/P&gt;

&lt;P&gt;crcSalt = &lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;That should give you the bits you need to add to the existing inputs.conf monitor stanza.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 22:09:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Windows-DHCP-Server-2003/m-p/26664#M9215</guid>
      <dc:creator>mdavis43</dc:creator>
      <dc:date>2012-11-09T22:09:09Z</dc:date>
    </item>
  </channel>
</rss>

