Splunk Enterprise

How to index different files with the same content

rayar
Path Finder

I have a folder with file generated once a day 

I would like to index all files event the files have the some content 

for example 

1_x.csv

2_x.csv 

.

.

.

I would like to index both files even they are identical 

the below is the input 


[monitor://\\ntnet\filestore1\information_security$\OS_Security_Splunk\*\...\*]
disabled = false
index = os_security
sourcetype = csv_current_time
crcSalt = <SOURCE>
initCrcLength = 1024
recursive = true
whitelist = \.csv$

Labels (1)
0 Karma

rayar
Path Finder

the message I have in the index=_intenal is 

File will not be read, seekptr checksum did not match (file=\\ntnet\filestore1\information_security$\OS_Security_Splunk\CMI\Tripwire\Compliance Report\Comcast_Ent\15-04-21_Comcast_Ent.csv). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

 

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.