<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cant add my complete list of sources. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32330#M178183</link>
    <description>&lt;P&gt;Find the relevant stanza in your inputs.conf and add:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt=&amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That's a literal "&lt;SOURCE&gt;".&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;From the inputs.conf doc:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt = &amp;lt;string&amp;gt;
* Use this setting to force Splunk to consume files that have matching CRCs (cyclic redundancy checks). (Splunk only performs CRC checks against the first few lines of a file. This behavior prevents Splunk from indexing the same file twice, even though you may have renamed it -- as, for example, with rolling log files. However, because the CRC is based on only the first few lines of the file, it is possible for legitimately different files to have matching CRCs, particularly if they have identical headers.)
* If set, &amp;lt;string&amp;gt; is added to the CRC.
* If set to the literal string &amp;lt;SOURCE&amp;gt; (including the angle brackets), the full directory path to the source file is added to the CRC. This ensures that each file being monitored has a unique CRC.   When crcSalt is invoked, it is usually set to &amp;lt;SOURCE&amp;gt;.
* Be cautious about using this attribute with rolling log files; it could lead to the log file being re-indexed after it has rolled. 
* Defaults to empty.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 21 Jun 2011 23:14:35 GMT</pubDate>
    <dc:creator>mw</dc:creator>
    <dc:date>2011-06-21T23:14:35Z</dc:date>
    <item>
      <title>Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32329#M178182</link>
      <description>&lt;P&gt;I've got 2 folders of config data- both have 21 files. &lt;/P&gt;

&lt;P&gt;Splunk is only adding 17 from one folder &amp;amp; 9 from the other.&lt;BR /&gt;
All these files contain very similar data &amp;amp; all the filename&lt;BR /&gt;
formats are identical&lt;/P&gt;

&lt;P&gt;I've tried things like deleting all files, running &lt;BR /&gt;
splunk clean all -f &lt;BR /&gt;
then creating all files new. &lt;BR /&gt;
Nogo. &lt;/P&gt;

&lt;P&gt;Tried instead of adding the directory but just adding full path &lt;BR /&gt;
to the files I noticed it was missing but it says that they are&lt;BR /&gt;
already added. &lt;/P&gt;

&lt;P&gt;Tried making a new directory of all the missing files &amp;amp; adding&lt;BR /&gt;
this new directory for splunk to consume- nogo. Still just sees&lt;BR /&gt;
26 sources. &lt;/P&gt;

&lt;P&gt;If I do a search on the source that is not listed- finds no hits&lt;BR /&gt;
&amp;amp; these files are not searchable in anyway through splunk. &lt;/P&gt;

&lt;P&gt;Looking for ways to troubleshoot this problem. &lt;/P&gt;

&lt;P&gt;Tried copying one of the directories to another server running&lt;BR /&gt;
another trial version (4.2.1) &amp;amp; it only saw the same 9 files. &lt;/P&gt;

&lt;P&gt;Checked the rights/permissions of the files, checked data.. all&lt;BR /&gt;
the same. Not sure why Splunk has a problem with these data files. &lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2011 22:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32329#M178182</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-21T22:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32330#M178183</link>
      <description>&lt;P&gt;Find the relevant stanza in your inputs.conf and add:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt=&amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That's a literal "&lt;SOURCE&gt;".&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;From the inputs.conf doc:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;crcSalt = &amp;lt;string&amp;gt;
* Use this setting to force Splunk to consume files that have matching CRCs (cyclic redundancy checks). (Splunk only performs CRC checks against the first few lines of a file. This behavior prevents Splunk from indexing the same file twice, even though you may have renamed it -- as, for example, with rolling log files. However, because the CRC is based on only the first few lines of the file, it is possible for legitimately different files to have matching CRCs, particularly if they have identical headers.)
* If set, &amp;lt;string&amp;gt; is added to the CRC.
* If set to the literal string &amp;lt;SOURCE&amp;gt; (including the angle brackets), the full directory path to the source file is added to the CRC. This ensures that each file being monitored has a unique CRC.   When crcSalt is invoked, it is usually set to &amp;lt;SOURCE&amp;gt;.
* Be cautious about using this attribute with rolling log files; it could lead to the log file being re-indexed after it has rolled. 
* Defaults to empty.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Jun 2011 23:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32330#M178183</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-06-21T23:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32331#M178184</link>
      <description>&lt;P&gt;Didnt work, when I check &lt;BR /&gt;
Manager » Data inputs » Files &amp;amp; directories &lt;/P&gt;

&lt;P&gt;it seems like it sees the files. (per below- sees 23 files- not sure why it sees 2 more&lt;BR /&gt;
- Maybe system files in there?)&lt;/P&gt;

&lt;P&gt;C:\getdisks  Regular Expresion diskinfo default  23  system Enabled | Disable  Clone | Delete&lt;BR /&gt;&lt;BR /&gt;
C:\getrgs  Regular Expresion rginfo default  23  system Enabled | Disable  Clone | Delete  &lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2011 23:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32331#M178184</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-21T23:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32332#M178185</link>
      <description>&lt;P&gt;So you edited inputs.conf and restarted?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2011 23:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32332#M178185</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-06-21T23:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32333#M178186</link>
      <description>&lt;P&gt;I tried stopping/starting splunk service. Nogo&lt;BR /&gt;
Then tried the splunk clean all -f process. Nogo&lt;BR /&gt;
Then just restarted the server- nogo.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2011 23:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32333#M178186</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-21T23:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32334#M178187</link>
      <description>&lt;P&gt;try searching the _internal index for any mention of one of the files that wasn't indexed: index=_internal myfilename&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32334#M178187</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2020-09-28T09:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32335#M178188</link>
      <description>&lt;P&gt;So what does this mean? I can search this &amp;amp; it finds the file. Still though it shows 26 sourcetypes. Its a trial license- this there are limiting usage restraints?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 17:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32335#M178188</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-23T17:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32336#M178189</link>
      <description>&lt;P&gt;What does it show you about the file if you look at the rest endpoint from the command line? From $SPLUNK_HOME/bin you can run 'splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus'. It should tell you what the status of the file is, if Splunk read it, what the size was when it was read, and to what percentage splunk read the file. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 18:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32336#M178189</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-06-23T18:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32337#M178190</link>
      <description>&lt;P&gt;Yes, it is, but your syntax is incorrect. It looks like you've called 'Filestatus', which is nonexistent, and not 'FileStatus'.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 19:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32337#M178190</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-06-23T19:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32338#M178191</link>
      <description>&lt;P&gt;Yea.. Its being ignored but Splunk refuses to index these files. I've put in the crcSalt command to all the missing files, stop/restart splunk service, restart server- still will not index these files. Still get that same error after all this: &lt;BR /&gt;
&lt;KEY name="type"&gt;ignored file (crc conflict, needs crcSalt)&lt;A href="https://answers.splunk.coms:key"&gt;/s:key&lt;/A&gt;&lt;/KEY&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 22:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32338#M178191</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-23T22:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32339#M178192</link>
      <description>&lt;P&gt;What is the exact syntax of the crcSalt setting you used in your inputs.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 22:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32339#M178192</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-06-23T22:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32340#M178193</link>
      <description>&lt;P&gt;[monitor://C:\getdisks]&lt;BR /&gt;
crcSalt=&lt;&gt;&lt;BR /&gt;
crcSalt=&lt;&gt;&lt;BR /&gt;
crcSalt=&lt;&gt;&lt;BR /&gt;
crcSalt=&lt;&gt;&lt;BR /&gt;
crcSalt=&lt;&gt;&lt;BR /&gt;
disabled = false&lt;BR /&gt;
followTail = 0&lt;BR /&gt;
sourcetype = diskinfo&lt;BR /&gt;
host_regex = :\getdisks\(.*)-DISK.txt$&lt;BR /&gt;
\cr&lt;BR /&gt;
what is CRCsalt? what in the output is different?&lt;BR /&gt;
all these scripts run the same every time- yet w/&lt;BR /&gt;
new files/folder/splunk installs- still has the &lt;BR /&gt;
issues with the same files.&lt;/&gt;&lt;/&gt;&lt;/&gt;&lt;/&gt;&lt;/&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 22:29:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32340#M178193</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-23T22:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32341#M178194</link>
      <description>&lt;P&gt;You should be doing this, verbatim, in your input:&lt;/P&gt;

&lt;P&gt;crcSalt=&lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;What you have there isn't going to work if that you've got in your inputs.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 23:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32341#M178194</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-06-23T23:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32342#M178195</link>
      <description>&lt;P&gt;Yea.. tried that several times too. &lt;BR /&gt;
as well as crcSalt=&lt;&gt; and crcSalt=&lt;&gt; nogo&lt;/&gt;&lt;/&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 23:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32342#M178195</guid>
      <dc:creator>clintla</dc:creator>
      <dc:date>2011-06-23T23:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cant add my complete list of sources.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32343#M178196</link>
      <description>&lt;P&gt;I'm not sure you're understanding.  You want to cut and paste this: crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;

&lt;P&gt;We're not telling you to replace &amp;lt;SOURCE&amp;gt; with the "source" of the data.  Literally put that string in there.  It will work if you do this correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 23:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Cant-add-my-complete-list-of-sources/m-p/32343#M178196</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-06-23T23:29:23Z</dc:date>
    </item>
  </channel>
</rss>

