Getting Data In

Seeing checksum errors when on-boarding data

power12
Communicator

Hello ,

i have logs in following path
/abc-logs/hosta/mods/stdout.240513-070854
/abc-logs/hostb/mods/stdout.240513-070854
/abc-logs/hostc/mods/stdout.240513-070854
/abc-logs/hostd.a.clusters.abc.com/mods/stdout.240206-084344
/abc-logs/hoste/mods/stdout.240513-070854

when I am trying monitor this path to get logs into splunk .I only get two files

.when checked internal logs i see following errors
05-16-2024 10:07:25.609 -0700 ERROR TailReader [1846912 tailreader0] - File will not be read, is too small to match seekptr checksum (file=/abc-logs/hosta/mods/stdout.240513-070854).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

A possible timestamp match (Fri Feb 13 15:31:30 2009) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: FileClassifier C:\abc-logs\hostd.a.clusters.abc.com\mods\stdout.240206-084344

I am using below props

[ mods ]
BREAK_ONLY_BEFORE_DATE=null
CHARSET=AUTO
CHECK_METHOD=entire_md5
DATETIME_CONFIG=CURRENT
LINE_BREAKER=([\r\n]+)
MAX_DAYS_AGO =2000
MAX_DAYS_HENCE=365
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
category=Custom
crcSalt=<SOURCE>
initCrcLength = 1048576



i tried changing the CHECK_METHOD to other options but it did not work 

Thanks in advance 

0 Karma

power12
Communicator

anyone faced this issues?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...