Splunk Enterprise

Why is data not indexed for data input?

mcohen13
Loves-to-Learn

I have index that suddenly stoped indexing data.

even after I entered crcSalt = <SOURCE> to the inputs.conf file data is not indexed anymore

the logs continue to show the following error:

"File will not be read, is too small to match seekptr checksum (file=<file_path>). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info."

any idea how to resolve this issue?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

crcSalt is very rarely a good option. Usually it's better to raise the initCrcLength if the file has a constant header which may interfere with the file recognition logic.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...