Getting Data In

How to decode which file being tracked in fishbucket is associated with which crc key?

govardha
Path Finder

Hello,

I have an universal forwarder configured to watch a file using the inputs.conf(crcSalt=<SOURCE>).  This works perfect, but I need to test sending the same file over and over again by prodding the local fishbucket instance to "forget" the file being monitored.

Unfortunately when I run the btprobe command, I get file not found.

btprobe -d /opt/splunk/var/lib/splunk/fishbucket/splunk_private_db --file /path/to/somefile --reset

I did a btool list input status, and the correct file shows up.

I then did a compute crc with the salt set to "/path/to/somefile" and used that in the btprobe command earlier and still doesn't work.

btprobe --compute-crc /path/to/somefile --salt "/path/to/somefile"

I used the results of the above command and did this and still found nothing.

splunk cmd btprobe -d $SPLUNK_DB/fishbucket/splunk_private_db -k ALL | egrep 0x34a86c35e2c71990

Can somebody point me in the right direction to get around this issue?

 

Labels (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...