Monitoring Splunk

why are my files being re-indexed?

toddblake
Explorer

I have a file that after being rotated to say file.01, is being re-indexed. My monitor is set to monitor file*, and

About an hour after it's indexed I can see in splunkd.og "WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file" I can see from the files mtime that the file hadn't changed, but I get that message all of a sudden, and the entire file is re-indexed.

I don't have any crcSalt settings, from what I gather I shouldn't need them. Because of this I'm getting logs re-indexed post-rotation since it thinks something about the file changed.

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi toddblacke

you should use the crcSalt option in your case, read the reason why in Mick's answer here -> http://splunk-base.splunk.com/answers/1568/windows-dhcp-log-files-too-small-to-match-seekptr-checksu...

cheers,
MuS

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...