Deployment Architecture

Data getting duplicated due to the error:WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

swmishra_splunk
Splunk Employee
Splunk Employee

I have a source logfile /var/splunk/log/user.log.I am sending the data from UF--->HF-->Indexer. And I am seeing the data is getting duplicated. Data is getting duplicated only from this source. I checked splunkd.log and got the below error:-

WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

Please let me know what can be done to fix the issue?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...