I was trying to load data via my auto index and I was getting a tail reader error because I think Splunk was reading in my file as a duplicate (this was at ~2 pm). Then around 9 pm- the file uploaded fine with all of the data. I checked _internal and the only information I have that contain the source file name are the below messages:
-0400 INFO Metrics - group=per_source_thruput
-0400 INFO LicenseUsage - type=Usage
Does anyone know why file uploaded ~7 hours later and can help me troubleshoot?
Sounds like splunk noticed the new file, but couldn't access it (because your upload process was keeping it fully locked somehow?)? And only later, it was able to access it and as a result still indexed it?