Hello,
I have gz files on a Windows server that I am monitoring using a universal forwarder and sending it to heavy forwarder --> Indexer
But The data indexed in Splunk is not in a readable format, so may I know what needs to be configured in props.conf to be able to read this data in Splunk?
[0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce]
This type of data comes in Splunk, but I'm unable to read it.
Also, I have another issue of a blocked aeq queue
due to which Splunk stopped indexing/sending data and am recieving a warning message as, "Could not send data to output queue (parsingQueue), retrying."
Thanks.
Hi @ips_mandar,
What type of data you are forwarding?
May be , you can try Splunk Stream app...
@vinod94 only .gz files I am forwarding and this app won't help
Splunk consumes gz files natively and you shouldn't have an issue. can you check out https://answers.splunk.com/answers/32273/how-to-indexed-gz-file-in-a-directory.html
https://answers.splunk.com/answers/217516/why-is-splunk-not-indexing-gz-files.html
Thanks @lakshman239
When I tried extracting gz files using 7zip to check file I was seeing [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce]
in file as well so not sure what could be issue..
Also I have another issue of blocked aeq queue due to which splunk stop indexing/sending data
That could also indicate that your 7zip file was not created properly. I don't think splunk supports 7zip, but you could check by taking a simple text file(log file), and 7zip it and upload via GUI on the dev splunk. You can then check the event breaking and props.conf.
regarding blocked queue, you need to check the data flowing from the datasource to indexers to see which all queue are blocked. If the file is huge, it can delay processing and temp the queue can be blocked. But if its persistent, it could indicate config/parsing issues etc..
I increased Queue Size to 600MB still it is getting Blocked ..I could see aeq queue is getting blocked