Deployment Architecture

Data getting duplicated due to the error:WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

swmishra_splunk
Splunk Employee
Splunk Employee

I have a source logfile /var/splunk/log/user.log.I am sending the data from UF--->HF-->Indexer. And I am seeing the data is getting duplicated. Data is getting duplicated only from this source. I checked splunkd.log and got the below error:-

WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

Please let me know what can be done to fix the issue?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...