Getting Data In

How do you set the props.conf file to read gz files in Splunk?

ips_mandar
Builder

Hello,

I have gz files on a Windows server that I am monitoring using a universal forwarder and sending it to heavy forwarder --> Indexer
But The data indexed in Splunk is not in a readable format, so may I know what needs to be configured in props.conf to be able to read this data in Splunk?

 [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce]

This type of data comes in Splunk, but I'm unable to read it.

Also, I have another issue of a blocked aeq queue due to which Splunk stopped indexing/sending data and am recieving a warning message as, "Could not send data to output queue (parsingQueue), retrying."

Thanks.

0 Karma

vinod94
Contributor

Hi @ips_mandar,

What type of data you are forwarding?

May be , you can try Splunk Stream app...

https://splunkbase.splunk.com/app/1809/

0 Karma

ips_mandar
Builder

@vinod94 only .gz files I am forwarding and this app won't help

0 Karma

lakshman239
Influencer
0 Karma

ips_mandar
Builder

Thanks @lakshman239
When I tried extracting gz files using 7zip to check file I was seeing [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce] in file as well so not sure what could be issue..
Also I have another issue of blocked aeq queue due to which splunk stop indexing/sending data

0 Karma

lakshman239
Influencer

That could also indicate that your 7zip file was not created properly. I don't think splunk supports 7zip, but you could check by taking a simple text file(log file), and 7zip it and upload via GUI on the dev splunk. You can then check the event breaking and props.conf.

regarding blocked queue, you need to check the data flowing from the datasource to indexers to see which all queue are blocked. If the file is huge, it can delay processing and temp the queue can be blocked. But if its persistent, it could indicate config/parsing issues etc..

https://answers.splunk.com/answers/150076/what-is-the-queue-named-aeq-and-how-to-increase-its-max-si...

0 Karma

ips_mandar
Builder

I increased Queue Size to 600MB still it is getting Blocked ..I could see aeq queue is getting blocked

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...