Getting Data In

About specification of "initCrcLength" option and "crcSalt" option.

yutaka1005
Builder
  • About initCrcLength

I know that changing initCrcLength option cause reindex and ignoreOlderThan option is workaround.
https://answers.splunk.com/answers/79250/will-changing-initcrclength-cause-data-to-be-reindexed.html

But if target is the log updated frequently, how can I avoid reindex?
Also, If I change initCrcLength, previous crc information in fishbucket will be cleared?

  • About crcSalt

Does adding crcSalt option causes reindex?
Also does it clear previous crc information in fishbucket?

If someone knows about it, please tell me.

0 Karma

vinod94
Contributor

hi @yutaka1005 ,

You can go through this link. This might help you.

https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Howlogfilerotationishandled

0 Karma

skalliger
Motivator

I am not sure that I understand your question. The functioning of crcSalt and initCrcLength are explained well in the docs. But what are you trying to archieve exactly?

Skalli

0 Karma

yutaka1005
Builder

Thank you for comment.

What I want to know is the following two points.

  • Is reindex occured if I set crcSalt = option?

  • The workaround for preventing reindex caused by changing initCrcLength is "ignoreOlderThan".
    But "ignoreOlderThan" option sees the update time of the file, so it will not be effective for files that are frequently updated.
    So I want to know method of reindex prevention caused by changing initCrcLength, when I monitoring frequently updated files.

VijaySrrie
Builder

Hi @yutaka1005 

 

You got the answer for your query?

If yes, can you please explain it?

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...