Getting Data In
Highlighted

After upgrading Splunk, why did one of my hosts stop reading files with errors "File too small to check seekcrc" and "Checksum for seekptr didn't match"?

Builder

After upgrading Splunk to the latest version, one of my indexers had stopped indexing data and reports the logs below in the splunkd.log.

01-11-2016 18:18:33.289 -0500 INFO WatchedFile - Will begin reading at offset=24997398 for file='/opt/splunkforwarder/var/log/splunk/metrics.log.1'.
01-11-2016 22:44:11.991 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-11-2016 22:44:35.020 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-11-2016 22:47:09.158 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:48:10.467 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:48:10.468 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:50:39.555 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:50:39.556 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:45.301 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 14:10:10.422 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.937 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.938 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.942 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 00:05:37.943 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:15.089 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-13-2016 11:47:32.105 -0500 ERROR TailingProcessor - File will not be read, is too small to match seekptr checksum (file=/opt/jboss/server/21cap/log/console.log). Last time we saw this initcrc, filename was different. You may wish to use a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.
01-13-2016 11:47:37.115 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:55.140 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
0 Karma
Highlighted

Re: After upgrading Splunk, why did one of my hosts stop reading files with errors "File too small to check seekcrc" and "Checksum for seekptr didn't match"?

Motivator

Hi Pavanae,

Could you please share the earliest version and the latest version you were upgrading? What are all the components you were updating?

Please check the below URL

http://docs.splunk.com/Documentation/Splunk/6.3.1/Installation/Aboutupgradingto6.3READTHISFIRST

Thanks,
V

0 Karma
Highlighted

Re: After upgrading Splunk, why did one of my hosts stop reading files with errors "File too small to check seekcrc" and "Checksum for seekptr didn't match"?

Builder

Earliest version :- 6.1.3
Latest version :- 6.3.2

0 Karma
Highlighted

Re: After upgrading Splunk, why did one of my hosts stop reading files with errors "File too small to check seekcrc" and "Checksum for seekptr didn't match"?

Motivator
0 Karma