Getting Data In
Provide Splunk Cloud feedback in this confidential UX survey by June 17
for a chance to win a $200 Amazon gift card!

CRCSALT = SOURCE but still getting error "File will not be read".

tb5821
Communicator

I have my inputs.conf setup like so:

[monitor:///var/log/java]
disabled = 0
index = myindex
sourcetype = metrics_csv
whitelist = metrics.*.csv
CRCSALT = <SOURCE>

But even though each filename is UNIQUE with a timestamp, etc, I still get the error that the "File will not be read"! Thoughts?

ERROR TailReader - File will not be read, is too small to match seekptr checksum ().  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.
Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

CRCSALT should be crcSalt.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

CRCSALT should be crcSalt.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

tb5821
Communicator

thanks - how do I confirm this is actually working though? I still see the same message in the logs

0 Karma

codebuilder
Motivator

You'll have to cycle the forwarder after correcting the typo.
Afterwards you can verify with tstats.
e.g.

|tstats count where index=myindex by source
0 Karma

codebuilder
Motivator

Did this resolve your issue? If so, please accept @richgalloway 's answer so that it can benefit others in the future.

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!