Security

how to handle ERROR ArchiveContext , Decompression error

kannu
Communicator

Hello Splunkers ,

Good day

I am stuck with one problem where i am monitoring .gz files using UF and getting the data on splunk as expected .
But when i have checked splunkd.log in that i am seeing below error

08-14-2019 02:34:43.158 -0500 ERROR ArchiveContext - From archive='E:\Tanium\Tanium Module Server\services\connect-files\output\SavedQuestion\Splunk-Running-Processes-with-MD5-Hash\Splunk-Running-Processes-with-MD5-Hash_2019-08-13T15-42-22.gz': Decompression error

Can anybody suggest how to get rid of it .

Thanks in advance

Kannu (manish kumar)

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...