<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic File indexed only occasionally in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338270#M166074</link>
    <description>&lt;P&gt;&lt;STRONG&gt;My input.conf file:&lt;/STRONG&gt;&lt;BR /&gt;
[monitor:///var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
crcSalt = SOURCE&lt;BR /&gt;
index = iss-nipa-clients&lt;BR /&gt;
sourcetype = nipa:clients:status&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;My props.conf file:&lt;/STRONG&gt;&lt;BR /&gt;
[nipa:clients:status]&lt;BR /&gt;
[source::/var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log]&lt;BR /&gt;
CHECK_METHOD = modtime&lt;BR /&gt;
DATETIME_CONFIG = NONE&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Extract from the forwarder splunkd.log:&lt;/STRONG&gt;&lt;BR /&gt;
09-13-2017 11:55:02.104 +0200 INFO  WatchedFile - Modtime is newer than stored, will reread file='/var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log'.&lt;BR /&gt;
09-13-2017 11:55:02.110 +0200 INFO  WatchedFile - Will begin reading at offset=0 for file='/var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log'.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;The file to be indexed:&lt;/STRONG&gt;&lt;BR /&gt;
File created at: 2017-09-13_11:59:01&lt;BR /&gt;
UNDEF,ip.ip.ip.ip:port,84,188,Wed Sep 13 11:58:16 2017,Tunnel_a&lt;BR /&gt;
c1115-ip.ip.ip.ip:port,19051077,18985566,Thu Aug 31 14:54:56 2017,Tunnel_a&lt;BR /&gt;
c1350,ip.ip.ip.ip:port,161253,160644,Wed Sep 13 09:24:57 2017,Tunnel_a&lt;BR /&gt;
c1255-1,ip.ip.ip.ip:port,176571,172050,Wed Sep 13 09:24:57 2017,Tunnel_a&lt;BR /&gt;
c1783-1,ip.ip.ip.ip:port,170017,175415,Wed Sep 13 09:24:59 2017,Tunnel_d&lt;BR /&gt;
c1215-1,ip.ip.ip.ip:port,167136,167643,Wed Sep 13 09:24:56 2017,Tunnel_d&lt;BR /&gt;
File created at: 2017-09-13_11:59:01&lt;/P&gt;

&lt;P&gt;This file is created every minute and according to &lt;STRONG&gt;splunkd.log&lt;/STRONG&gt; it is also read every minute, but not indexed &lt;STRONG&gt;only periodicaly&lt;/STRONG&gt;. &lt;BR /&gt;
The created time stamp on the header and trailer is changing every minute as the creatation time of the file.&lt;/P&gt;

&lt;P&gt;Why is splunk not indexing this file every minute!!!!????&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:46:55 GMT</pubDate>
    <dc:creator>MuratKuru</dc:creator>
    <dc:date>2020-09-29T15:46:55Z</dc:date>
    <item>
      <title>File indexed only occasionally</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338270#M166074</link>
      <description>&lt;P&gt;&lt;STRONG&gt;My input.conf file:&lt;/STRONG&gt;&lt;BR /&gt;
[monitor:///var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
crcSalt = SOURCE&lt;BR /&gt;
index = iss-nipa-clients&lt;BR /&gt;
sourcetype = nipa:clients:status&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;My props.conf file:&lt;/STRONG&gt;&lt;BR /&gt;
[nipa:clients:status]&lt;BR /&gt;
[source::/var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log]&lt;BR /&gt;
CHECK_METHOD = modtime&lt;BR /&gt;
DATETIME_CONFIG = NONE&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Extract from the forwarder splunkd.log:&lt;/STRONG&gt;&lt;BR /&gt;
09-13-2017 11:55:02.104 +0200 INFO  WatchedFile - Modtime is newer than stored, will reread file='/var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log'.&lt;BR /&gt;
09-13-2017 11:55:02.110 +0200 INFO  WatchedFile - Will begin reading at offset=0 for file='/var/log/openvpn/&lt;EM&gt;hostname&lt;/EM&gt;_vpnStatus.log'.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;The file to be indexed:&lt;/STRONG&gt;&lt;BR /&gt;
File created at: 2017-09-13_11:59:01&lt;BR /&gt;
UNDEF,ip.ip.ip.ip:port,84,188,Wed Sep 13 11:58:16 2017,Tunnel_a&lt;BR /&gt;
c1115-ip.ip.ip.ip:port,19051077,18985566,Thu Aug 31 14:54:56 2017,Tunnel_a&lt;BR /&gt;
c1350,ip.ip.ip.ip:port,161253,160644,Wed Sep 13 09:24:57 2017,Tunnel_a&lt;BR /&gt;
c1255-1,ip.ip.ip.ip:port,176571,172050,Wed Sep 13 09:24:57 2017,Tunnel_a&lt;BR /&gt;
c1783-1,ip.ip.ip.ip:port,170017,175415,Wed Sep 13 09:24:59 2017,Tunnel_d&lt;BR /&gt;
c1215-1,ip.ip.ip.ip:port,167136,167643,Wed Sep 13 09:24:56 2017,Tunnel_d&lt;BR /&gt;
File created at: 2017-09-13_11:59:01&lt;/P&gt;

&lt;P&gt;This file is created every minute and according to &lt;STRONG&gt;splunkd.log&lt;/STRONG&gt; it is also read every minute, but not indexed &lt;STRONG&gt;only periodicaly&lt;/STRONG&gt;. &lt;BR /&gt;
The created time stamp on the header and trailer is changing every minute as the creatation time of the file.&lt;/P&gt;

&lt;P&gt;Why is splunk not indexing this file every minute!!!!????&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338270#M166074</guid>
      <dc:creator>MuratKuru</dc:creator>
      <dc:date>2020-09-29T15:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: File indexed only occasionally</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338271#M166075</link>
      <description>&lt;P&gt;Hi MuratKuru,&lt;BR /&gt;
at first why you have two stanzas in props.conf? the first one is empty and only the second one is read; try to use only sourcetype stanza ( &lt;CODE&gt;[nipa:clients:status]&lt;/CODE&gt; ) in your props.conf.&lt;BR /&gt;
In addition if you have &lt;CODE&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/CODE&gt; and you index always the same file, you could have problems.&lt;BR /&gt;
So try to modify inputs.conf and props.conf and check if the situation is the same or not.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 10:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338271#M166075</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-14T10:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: File indexed only occasionally</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338272#M166076</link>
      <description>&lt;P&gt;Hi Giuseppe&lt;BR /&gt;
I have made the suggested changes, but still have the save problem.&lt;BR /&gt;
Regards,&lt;BR /&gt;
Murat Kuru&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 06:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338272#M166076</guid>
      <dc:creator>MuratKuru</dc:creator>
      <dc:date>2017-09-15T06:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: File indexed only occasionally</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338273#M166077</link>
      <description>&lt;P&gt;Hi Murat Kuru,&lt;BR /&gt;
Is there a reason because you perform a File checksum configuration using &lt;CODE&gt;CHECK_METHOD = modtime&lt;/CODE&gt; ?&lt;BR /&gt;
Try to cut this option.&lt;BR /&gt;
bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 09:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338273#M166077</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-15T09:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: File indexed only occasionally</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338274#M166078</link>
      <description>&lt;P&gt;I agree with @cusello. The following speaks about a similar issue - &lt;A href="https://answers.splunk.com/answers/12808/log-file-in-etc-log-is-reindexed-resulting-in-duplicate-events.html"&gt;Log file in /etc/log is reindexed resulting in duplicate events&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;CHECK_METHOD = modtime&lt;/CODE&gt; seems there to be the culprit...&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 02:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338274#M166078</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-09-18T02:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: File indexed only occasionally</title>
      <link>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338275#M166079</link>
      <description>&lt;P&gt;If this answer satisfies your question, please accept or upvote it.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 11:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/File-indexed-only-occasionally/m-p/338275#M166079</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-20T11:24:54Z</dc:date>
    </item>
  </channel>
</rss>

