Getting Data In

Files not being Indexed

ShaneNewman
Motivator

We have files that are not being indexed, yet they are seen by Splunk. We have 38 files FTP'ed to a file folder which Splunk monitors every hour. Each hour, the previous 24 hours worth of data is dumped, just in case the job does not run as expected, this keeps us from having data loss. Being this way, we know that Splunk sees the old data as duplicate data, so we use this config to solve it:

[monitor://E:\inetpub\ftproot\NPR\PROD] 
sourcetype = meditech_npr 
index = capsule_npr 
crcSalt = <SOURCE> 

Until the upgrade to Splunk 6/6.0.1, this has worked fine, it no longer appears to work though. It is of extreme importance that this issue is resolved immediately. Currently, I am having to delete the entire _thefishbucket index every few hours to ensure that data is getting indexed properly.

Any help would be greatly appreciated!

0 Karma
1 Solution

ShaneNewman
Motivator

This is the message I got back from Splunk Support.

It looks like this behavior has been identified as bug SPL-76980 and a code change has already been made that should resolved the issue, being included tentatively in version 6.0.2.

View solution in original post

0 Karma

ShaneNewman
Motivator

This is the message I got back from Splunk Support.

It looks like this behavior has been identified as bug SPL-76980 and a code change has already been made that should resolved the issue, being included tentatively in version 6.0.2.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...