Deployment Architecture

Migrate splunkforwarder on to a new server

New Member

We have a jetty server "geoappserver" with IP and in that its already running splunkforwarder and was working fine. We are using this hostname and in splunk this server is listing ans log files are able to search.

Its a opensuse server. Now we are moving this server to a Oracle Linux server and we moved jetty server in which all logs files are on same location.

We moved splunkforwarder to new Oracle linux server and bring down opensuse server.

Started splunk service and is running but when we search in splunk server its listing old data only and from new server logs are displaying.

06-20-2018 05:53:43.167 -0700 ERROR TailReader - File will not be read, seekptr checksum did not match (file=/opt/jetty/logs/jetty-services.log).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at for more info.
06-20-2018 05:53:43.169 -0700 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_ui_access.log'.
06-20-2018 05:53:43.172 -0700 INFO  WatchedFile - Will begin reading at offset=287733 for file='/opt/splunkforwarder/var/log/splunk/metrics.log'.
06-20-2018 05:53:43.173 -0700 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/scheduler.log'.

We moved entire splunkforwarder to new server and started splunk again. So please let me any other chnage we need to do on this.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...