Getting Data In

How to set up a stanza batch to index same file?

arthurf
Explorer

Hello,

I set up my batch stanza to delete the file once indexed, but sometime, the file can't be due to permission error and the same file is indexed multiple time.

I used both of the following options:

initCrcLength = 2000
crcSalt = 

But the same file is still indexed again.
How can I set up the stanza not to read the same file?
Is that possible with batch stanza which deletes the files? (move_policy = sinkhole)

0 Karma

tiagofbmm
Influencer

The move_policy MUST be sinkhole for that to work as you want.

move_policy = sinkhole
* This setting is required. You must include "move_policy = sinkhole"
when you define batch inputs.

arthurf
Explorer

The move_policy is set.
Here my actual configuration :

[batch://FOLDER/Pattern]
sourcetype = fluxeditique:cabestan:dtr:in:planapurement3
index=cabestan
initCrcLength = 2000
move_policy = sinkhole

I replaced "crcSalt = " with "initCrcLength = 2000" but the result is the same.

0 Karma

tiagofbmm
Influencer

CRC settings belong to the monitor::// stanzas, not the batch ones.

It seems you need to take care of the deleting permissions of the files for Splunk user to be able to delete them.

arthurf
Explorer

Ok, so if get you correctly, it's not possible to prevent the indexation of the same file with batch stanza ?
And we need to ensure that the same log file is not generated twice, right ?

0 Karma

tiagofbmm
Influencer

Yes, with batch you don't get that possibility

arthurf
Explorer

Thanks for the confirmation.

Have a good day.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...