We see the message INFO WatchedFile - Will begin reading at offset=313 for file xxxx and the input file is exactly 313 characters and it was not indexed so far. We added crcSalt = <SOURCE> and it didn't help.
INFO WatchedFile - Will begin reading at offset=313 for file xxxx
crcSalt = <SOURCE>
How can we do to get this file to be indexed?
what does ./splunk list inputstatus say for this input?
./splunk list inputstatus
Sounds like we knew about the file and have the seekptr in the fishbucket. Maybe try and zap the fishbucket?
./splunk cmd btprobe -d /opt/splunkforwarder/var/lib/splunk/fishbucket/splunk_private_db --file /var/log/messages --reset
Are you sure we haven't indexed it? Have you searched all time?
Perfect. I searched all time...
I ran the command and got back -
Using logging configuration at /opt/splunk/splunkforwarder/etc/log-cmdline.cfg.
key=0xc70a454221239041 scrc=0xefd9b0699540a4c0 sptr=314 fcrc=0xd2febf0eb34e3560 flen=0 mdtm=1501003479 wrtm=1501043870
What does it mean?