Getting Data In

Seeing checksum errors when on-boarding data

power12
Communicator

Hello ,

i have logs in following path
/abc-logs/hosta/mods/stdout.240513-070854
/abc-logs/hostb/mods/stdout.240513-070854
/abc-logs/hostc/mods/stdout.240513-070854
/abc-logs/hostd.a.clusters.abc.com/mods/stdout.240206-084344
/abc-logs/hoste/mods/stdout.240513-070854

when I am trying monitor this path to get logs into splunk .I only get two files

.when checked internal logs i see following errors
05-16-2024 10:07:25.609 -0700 ERROR TailReader [1846912 tailreader0] - File will not be read, is too small to match seekptr checksum (file=/abc-logs/hosta/mods/stdout.240513-070854).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

A possible timestamp match (Fri Feb 13 15:31:30 2009) is outside of the acceptable time window. If this timestamp is correct, consider adjusting MAX_DAYS_AGO and MAX_DAYS_HENCE. Context: FileClassifier C:\abc-logs\hostd.a.clusters.abc.com\mods\stdout.240206-084344

I am using below props

[ mods ]
BREAK_ONLY_BEFORE_DATE=null
CHARSET=AUTO
CHECK_METHOD=entire_md5
DATETIME_CONFIG=CURRENT
LINE_BREAKER=([\r\n]+)
MAX_DAYS_AGO =2000
MAX_DAYS_HENCE=365
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
category=Custom
crcSalt=<SOURCE>
initCrcLength = 1048576



i tried changing the CHECK_METHOD to other options but it did not work 

Thanks in advance 

0 Karma

power12
Communicator

anyone faced this issues?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...