Getting Data In

How do you set the props.conf file to read gz files in Splunk?

ips_mandar
Builder

Hello,

I have gz files on a Windows server that I am monitoring using a universal forwarder and sending it to heavy forwarder --> Indexer
But The data indexed in Splunk is not in a readable format, so may I know what needs to be configured in props.conf to be able to read this data in Splunk?

 [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce]

This type of data comes in Splunk, but I'm unable to read it.

Also, I have another issue of a blocked aeq queue due to which Splunk stopped indexing/sending data and am recieving a warning message as, "Could not send data to output queue (parsingQueue), retrying."

Thanks.

0 Karma

vinod94
Contributor

Hi @ips_mandar,

What type of data you are forwarding?

May be , you can try Splunk Stream app...

https://splunkbase.splunk.com/app/1809/

0 Karma

ips_mandar
Builder

@vinod94 only .gz files I am forwarding and this app won't help

0 Karma

lakshman239
Influencer
0 Karma

ips_mandar
Builder

Thanks @lakshman239
When I tried extracting gz files using 7zip to check file I was seeing [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce] in file as well so not sure what could be issue..
Also I have another issue of blocked aeq queue due to which splunk stop indexing/sending data

0 Karma

lakshman239
Influencer

That could also indicate that your 7zip file was not created properly. I don't think splunk supports 7zip, but you could check by taking a simple text file(log file), and 7zip it and upload via GUI on the dev splunk. You can then check the event breaking and props.conf.

regarding blocked queue, you need to check the data flowing from the datasource to indexers to see which all queue are blocked. If the file is huge, it can delay processing and temp the queue can be blocked. But if its persistent, it could indicate config/parsing issues etc..

https://answers.splunk.com/answers/150076/what-is-the-queue-named-aeq-and-how-to-increase-its-max-si...

0 Karma

ips_mandar
Builder

I increased Queue Size to 600MB still it is getting Blocked ..I could see aeq queue is getting blocked

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...