Splunk Enterprise

TailReader - File will not be read, is too small to match seekptr checksum

gitingua
Communicator
ERROR TailReader - File will not be read, is too small to match seekptr checksum (file=c:\logs\MailBoxAudit\mailboxaudit_23_12_2021_13_48.csv). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.
 
 
inputs.conf
 

/opt/splunk/etc/deployment-apps/TA-Exchange-Mailbox/local/inputs.conf 

[monitor://c:\logs\MailBoxAudit]

whitelist=\.csv$|\.CSV$

sourcetype=csv

index= indexname

disabled=false

crcSalt = <SOURCE>

initCrcLength=8192

after making a change to the file inputs.conf. i ran the command

/opt/splunk/bin/splunk reload deploy-server -class heavy_forwarders

for the changes to be accepted

the file comes to the index, but it does not start up some

 

what could be the problem ?

 

 

 

 
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...