<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk skips or delays indexing of the log file during the rotation occassionaly in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408264#M167886</link>
    <description>&lt;P&gt;Hi @ankithnageshshetty,&lt;/P&gt;

&lt;P&gt;When you said log rotation, does the name of the file change? If so, then splunk doesn't monitor &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Howlogfilerotationishandled"&gt;log rotations&lt;/A&gt; by default. However, you can adjust your inputs(.conf) to achieve this.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2018 17:33:14 GMT</pubDate>
    <dc:creator>sudosplunk</dc:creator>
    <dc:date>2018-08-14T17:33:14Z</dc:date>
    <item>
      <title>Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408263#M167885</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;I have an issue where Splunk some times skips to index the log file during the rotation or delays the indexing during the log rotation.&lt;/P&gt;

&lt;P&gt;This issue is only for specific file.So we can rule out the blocked queue, timezone, network throughput or slow performing indexer/forwarder.&lt;BR /&gt;
Sar report showed good iostat cpu and mem stats on the forwarder.&lt;/P&gt;

&lt;P&gt;I don't see initcrclength(crcSalT) or file_descriptor related issue in the splunk log.&lt;BR /&gt;
In fact there are no error in the splunk log during this issue.&lt;/P&gt;

&lt;P&gt;Any guidance is highly appreciated.&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Ankith&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408263#M167885</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-14T15:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408264#M167886</link>
      <description>&lt;P&gt;Hi @ankithnageshshetty,&lt;/P&gt;

&lt;P&gt;When you said log rotation, does the name of the file change? If so, then splunk doesn't monitor &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Howlogfilerotationishandled"&gt;log rotations&lt;/A&gt; by default. However, you can adjust your inputs(.conf) to achieve this.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 17:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408264#M167886</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-14T17:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408265#M167887</link>
      <description>&lt;P&gt;Yes..the name of the file changes..&lt;BR /&gt;
usually splunk continues to read the new file after the rotation. But some times splunk either skips the new file or delayes in indexing.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 17:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408265#M167887</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-14T17:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408266#M167888</link>
      <description>&lt;P&gt;How frequently the file roles? How much data does the file contains?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 19:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408266#M167888</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-08-14T19:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408267#M167889</link>
      <description>&lt;P&gt;Hello Somesoni,&lt;/P&gt;

&lt;P&gt;File rotates every 30 minutes and size is 96MB.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 14:58:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408267#M167889</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-15T14:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408268#M167890</link>
      <description>&lt;P&gt;Depending upon the spike in data logging during those 30mins, there can be slowness in logs being ingested. Could you please provide monitoring stanza (inputs.conf) ? Also, how many rolled files do you keep and how are they renamed? (e.g. if myapp.log is name of monitored file, does it roll to myapp.log.1 first, then myapp.log.1 is renamed myapp.log.2 and next myapp.log is rolled as myapp.log.1 etc.)&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 15:16:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408268#M167890</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-08-15T15:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408269#M167891</link>
      <description>&lt;P&gt;Hi somesoni,&lt;/P&gt;

&lt;P&gt;Thanks for the prompt replies.&lt;/P&gt;

&lt;P&gt;monitoring stanza:&lt;BR /&gt;
[monitor:///app/logs/.../access]&lt;BR /&gt;
sourcetype=ldap_access&lt;BR /&gt;
index=XXX&lt;BR /&gt;
ignoreOlderThan=14d&lt;/P&gt;

&lt;P&gt;rotated file name: access.20180815152048Z . Basically it appends date and 6 digit number and "Z" to the file name. &lt;/P&gt;

&lt;P&gt;1435 rotated files are present on the FS and retention is 56 days.&lt;/P&gt;

&lt;P&gt;There is no information about file descriptor issue in the logs.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 15:31:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408269#M167891</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-15T15:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408270#M167892</link>
      <description>&lt;P&gt;So, in your monitoring stanza, the last access (&lt;CODE&gt;.../access&lt;/CODE&gt;) is the file name Or directory? Ideally your monitoring stanza should be able to include rolled logs (you'd be monitoring both regularly written file and the rolled log file) as you're not using &lt;CODE&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/CODE&gt; (don't monitor rolled logs and use above crcSalt setting as it'll cause whole rolled log to be ingested again). With that, since Splunk is monitoring both regular log (will get each entry as they're new) and rolled logs (will not get everything else Splunk would recognize that it has already read those content, but will ingest anything that wasn't read).&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 15:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408270#M167892</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-08-15T15:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408271#M167893</link>
      <description>&lt;P&gt;Hi somesoni,&lt;/P&gt;

&lt;P&gt;access is file name and not the directory.&lt;/P&gt;

&lt;P&gt;The actual file name is just "access" as mentioned in the monitoring stanza.&lt;/P&gt;

&lt;P&gt;After the rotation new "access" file is created and old file is renamed to access.20180815152048Z&lt;/P&gt;

&lt;P&gt;So I believe Splunk is only monitoring access here. &lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 15:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408271#M167893</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-15T15:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408272#M167894</link>
      <description>&lt;P&gt;Ok.. So try this for your monitoring stanza. You should see improvement. (restart after making change if making change directly)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///app/logs/.../access*]
sourcetype=ldap_access
index=XXX
ignoreOlderThan=14d
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 15 Aug 2018 16:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408272#M167894</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-08-15T16:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408273#M167895</link>
      <description>&lt;P&gt;Will this not read the rotated file?  creating  duplicate indexing?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 18:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408273#M167895</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-15T18:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408274#M167896</link>
      <description>&lt;P&gt;There is a bug for this in various versions.  When the file rotates, Splunk stops reading the file until the file rotates again.  At that point it ingests both files (catches up).  The work around is to configure &lt;EM&gt;time_before_close = 1&lt;/EM&gt; under the relevant input.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://&amp;lt;path&amp;gt;]
time_before_close = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you are on 6.6.x, this is fixed in 6.6.4:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.4/ReleaseNotes/6.6.4#Data_input_issues" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.4/ReleaseNotes/6.6.4#Data_input_issues&lt;/A&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;SPL-142334, SPL-143553, SPL-145370, SPL-145978   logs are delayed in reading after rotation&lt;/EM&gt; &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This particular version of the bug is also fixed in:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;7.1.0 (SPL-143553)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;7.0.1 (SPL-145978)&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I have seen this in 6.4.x as well and the provided work around (listed above) resolved the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408274#M167896</guid>
      <dc:creator>jcrabb_splunk</dc:creator>
      <dc:date>2020-09-29T20:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408275#M167897</link>
      <description>&lt;P&gt;Thanks jcrabb for the update.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 13:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408275#M167897</guid>
      <dc:creator>ankithnageshshe</dc:creator>
      <dc:date>2018-08-16T13:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408276#M167898</link>
      <description>&lt;P&gt;Hi, I am having the same issue with IIS logs and right now we are in 6.6.3. We are not able to upgrade our versions sooner because of some other issues we are having. So my question is, is this issue resolved for 6.6.3 or is it just above 6.6.4.  we have tried adding "time_before_close = 10" in our inputs.conf, but we did not see any improvements or changes.  Thanks everyone!!!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408276#M167898</guid>
      <dc:creator>vinaykata</dc:creator>
      <dc:date>2020-09-29T22:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408277#M167899</link>
      <description>&lt;P&gt;Fixed in 6.6.4 and the other versions mentioned by jcrabb, you will need to upgrade to a newer version to avoid the issue&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 21:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408277#M167899</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-12-05T21:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk skips or delays indexing of the log file during the rotation occassionaly</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408278#M167900</link>
      <description>&lt;P&gt;Is it possible that bugfix never made it to the 7.2 tree?&lt;/P&gt;

&lt;P&gt;We experience this issue on forwarder 7.2.6, and setting time_before_close to 1 seems to help so far.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-skips-or-delays-indexing-of-the-log-file-during-the/m-p/408278#M167900</guid>
      <dc:creator>knielsen</dc:creator>
      <dc:date>2020-09-30T03:06:40Z</dc:date>
    </item>
  </channel>
</rss>

