Getting Data In

initcrc error

rjulie
New Member

hi,

I have a lot of error when splunk try to decrompess .gz files

my inputs.conf :

[monitor://D:\xxxxxx\]
source = file.bluecoat
sourcetype = bluecoat:proxysg:access:file
disabled = false
index=proxy
current_only=0

Error Message

ERROR ArchiveContext - From archive='D:\SFTP\Logs_proxy\FR000_ALOG_EU-PAR-BC101_inet_20190130_125039_UTC.log.gz':  Decompression error
DEBUG ArchiveProcessor -   Found no initcrc match for this stream, will re-read entire file.
DEBUG ArchiveProcessor -   This archive stream's initcrc=0x7154d22c05d963eb.

I don't have a solution and you ?

Thank you in advance

0 Karma

woodcock
Esteemed Legend

I would open a support case.

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...