Getting Data In
Highlighted

Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

Hi,

I have to monitor all files inside one directory. But the tiny sized files are not getting into Splunk while all other files are duly getting indexed. i used CRCSalt parameters and Below is my config settings for inputs file.

[monitor://L:\XYZ.2.0\XYZlogs\*]
disabled = false
index = app_XYZ
sourcetype = _json
crcSalt = Source in greater than and less than sign
initCrcLength = 256

Please tell us what am I missing out on.

Thanks

0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Influencer

make sure the path is correct, try giving complete file name.

0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

Yes path is accurate given other large files are duly getting indexed in splunk.

0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

Are the files smaller than the 256 bytes?

Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

File size is like 1-5KBs.

0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

Also i just discovered that few of the data is going into "lastchanceindex". Why is that the case.

0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Esteemed Legend

You have the setting wrong. Use this exactly (do NOT change anything at all):

crcSalt=<SOURCE>
0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

Yes its indeed the same settings.

crcSalt=SOURCE with angular brackets

0 Karma
Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Esteemed Legend

Do you LITERALLY have this:

crcSalt=<SOURCE>

Or have you substituted the word SOURCE for something else like this:

crcSalt=</your/path/file>

YOU MUST NOT DO THE LATTER! YOU MUST DO THE FORMER!

Highlighted

Re: Why is Splunk unable to index logs with very small sizes [in KB] but is able to parse other files from that directory?

Explorer

Yes i have done the former setting only.

0 Karma