<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Log ingestion issues in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376304#M6074</link>
    <description>&lt;P&gt;This could be related to multiple issues&lt;BR /&gt;
1. crcSalt  =&amp;gt; By default, the Splunk only performs CRCs against the first few lines of a file. so if the lines are exactly same on these files for the default settings, it may NOT index&lt;BR /&gt;
2. initCrcLength =&amp;gt; default is 256 bytes ; How much of a file, in bytes, that the input reads before trying to&lt;BR /&gt;
  identify whether it is a file that has already been seen. You might want to  adjust this if you have many files with common headers&lt;BR /&gt;
3. Do a btool of inputs to see if your settings are overriden in some other app&lt;/P&gt;

&lt;P&gt;you need to give the exact samples/btool output in the question for us to help you further&lt;/P&gt;

&lt;P&gt;Good link to read about =&amp;gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt;&lt;BR /&gt;
and of course inputs.conf specification&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2019 15:11:01 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2019-05-16T15:11:01Z</dc:date>
    <item>
      <title>Splunk Log ingestion issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376303#M6073</link>
      <description>&lt;P&gt;Currently i am facing a issue , i am monitoring a directory that has over 14000 files i am getting few files are ingesting to splunk and few files are not ingesting , currently i am using these two stanzas in my input.conf file disabled = false&lt;BR /&gt;
recursive = true  , anyone  has face similar issue ?&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 14:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376303#M6073</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-05-16T14:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Log ingestion issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376304#M6074</link>
      <description>&lt;P&gt;This could be related to multiple issues&lt;BR /&gt;
1. crcSalt  =&amp;gt; By default, the Splunk only performs CRCs against the first few lines of a file. so if the lines are exactly same on these files for the default settings, it may NOT index&lt;BR /&gt;
2. initCrcLength =&amp;gt; default is 256 bytes ; How much of a file, in bytes, that the input reads before trying to&lt;BR /&gt;
  identify whether it is a file that has already been seen. You might want to  adjust this if you have many files with common headers&lt;BR /&gt;
3. Do a btool of inputs to see if your settings are overriden in some other app&lt;/P&gt;

&lt;P&gt;you need to give the exact samples/btool output in the question for us to help you further&lt;/P&gt;

&lt;P&gt;Good link to read about =&amp;gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt;&lt;BR /&gt;
and of course inputs.conf specification&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 15:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376304#M6074</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-16T15:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Log ingestion issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376305#M6075</link>
      <description>&lt;P&gt;so do i need to add crcSalt= or just  crcSalt =&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 21:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Log-ingestion-issues/m-p/376305#M6075</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-05-16T21:36:27Z</dc:date>
    </item>
  </channel>
</rss>

