Getting Data In

Seeing checksum errors when on-boarding data

power12
Communicator

Hello ,

i have logs in following path
/abc-logs/hosta/mods/stdout.240513-070854
/abc-logs/hostb/mods/stdout.240513-070854
/abc-logs/hostc/mods/stdout.240513-070854
/abc-logs/hostd.a.clusters.abc.com/mods/stdout.240206-084344
/abc-logs/hoste/mods/stdout.240513-070854

when I am trying monitor this path to get logs into splunk .I only get two files

.when checked internal logs i see following errors
05-16-2024 10:07:25.609 -0700 ERROR TailReader [1846912 tailreader0] - File will not be read, is too small to match seekptr checksum (file=/abc-logs/hosta/mods/stdout.240513-070854).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

A possible timestamp match (Fri Feb 13 15:31:30 2009) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: FileClassifier C:\abc-logs\hostd.a.clusters.abc.com\mods\stdout.240206-084344

I am using below props

[ mods ]
BREAK_ONLY_BEFORE_DATE=null
CHARSET=AUTO
CHECK_METHOD=entire_md5
DATETIME_CONFIG=CURRENT
LINE_BREAKER=([\r\n]+)
MAX_DAYS_AGO =2000
MAX_DAYS_HENCE=365
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
category=Custom
crcSalt=<SOURCE>
initCrcLength = 1048576



i tried changing the CHECK_METHOD to other options but it did not work 

Thanks in advance 

0 Karma

power12
Communicator

anyone faced this issues?

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...