I have a new 5.0 splunk server that is the indexer and search head.
I have one forwarder sending logs.
All is working well but!
One directory of log files. Splunk is only reading the first line of the files in this directory.
11-09-2012 08:33:43.250 -0600 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jrun4/logs/server-2-event.log'.
11-09-2012 08:33:43.250 -0600 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jrun4/logs/server-2-event.log'.
Here is what is in my inputs.conf
crcSalt = <SOURCE>
disabled = false
I just recently add the crcSalt = <SOURCE> and restarted the forwarder. I'm still not getting the entire file indexed.
NOTE: I do have the word "SOURCE" between the greater than and less than symbols. It just didn't show up when typeing this question.