Getting Data In

Files not being Indexed

ShaneNewman
Motivator

We have files that are not being indexed, yet they are seen by Splunk. We have 38 files FTP'ed to a file folder which Splunk monitors every hour. Each hour, the previous 24 hours worth of data is dumped, just in case the job does not run as expected, this keeps us from having data loss. Being this way, we know that Splunk sees the old data as duplicate data, so we use this config to solve it:

[monitor://E:\inetpub\ftproot\NPR\PROD] 
sourcetype = meditech_npr 
index = capsule_npr 
crcSalt = <SOURCE> 

Until the upgrade to Splunk 6/6.0.1, this has worked fine, it no longer appears to work though. It is of extreme importance that this issue is resolved immediately. Currently, I am having to delete the entire _thefishbucket index every few hours to ensure that data is getting indexed properly.

Any help would be greatly appreciated!

0 Karma
1 Solution

ShaneNewman
Motivator

This is the message I got back from Splunk Support.

It looks like this behavior has been identified as bug SPL-76980 and a code change has already been made that should resolved the issue, being included tentatively in version 6.0.2.

View solution in original post

0 Karma

ShaneNewman
Motivator

This is the message I got back from Splunk Support.

It looks like this behavior has been identified as bug SPL-76980 and a code change has already been made that should resolved the issue, being included tentatively in version 6.0.2.

0 Karma
Get Updates on the Splunk Community!

Splunk Certification Support Alert | Pearson VUE Outage

Splunk Certification holders and candidates!  Please be advised of an upcoming system maintenance period for ...

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...