Getting Data In

WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file - Does this mean it exists?

exocore123
Path Finder

I am writing a splunk forwarder to our own splunk instance. For some reason, my logs are not shipping and its frustrating. The docker instance we have is fargate so I can not ssh into the instance and debug whether the logs exist.

One of my splunkforwarder logs indicated

WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file

Does this mean it sees this file/this file existed? I want to make sure that my multicontainer are working as -

A and B - where B is the splunkforwarder

  1. A is wring to the location (/app/logs) - means this file must have been created by A
  2. B using VolumeFrom is about to mount the volume from A
  3. B has access to the logs within /app/logs/
0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...