Deployment Architecture

Data getting duplicated due to the error:WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

swmishra_splunk
Splunk Employee
Splunk Employee

I have a source logfile /var/splunk/log/user.log.I am sending the data from UF--->HF-->Indexer. And I am seeing the data is getting duplicated. Data is getting duplicated only from this source. I checked splunkd.log and got the below error:-

WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

Please let me know what can be done to fix the issue?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...