Security

how to handle ERROR ArchiveContext , Decompression error

kannu
Communicator

Hello Splunkers ,

Good day

I am stuck with one problem where i am monitoring .gz files using UF and getting the data on splunk as expected .
But when i have checked splunkd.log in that i am seeing below error

08-14-2019 02:34:43.158 -0500 ERROR ArchiveContext - From archive='E:\Tanium\Tanium Module Server\services\connect-files\output\SavedQuestion\Splunk-Running-Processes-with-MD5-Hash\Splunk-Running-Processes-with-MD5-Hash_2019-08-13T15-42-22.gz': Decompression error

Can anybody suggest how to get rid of it .

Thanks in advance

Kannu (manish kumar)

Tags (2)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...