Splunk Search

File too small....but not

caphrim007
Path Finder

I have these info messages popping up in my splunk install every couple of seconds

09-25-2012 09:37:40.378 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/logging/syslog-ng/everything'.
09-25-2012 09:37:40.378 -0500 INFO  WatchedFile - Will begin reading at offset=0 for file='/logging/syslog-ng/everything'.

But the file that it is monitoring is growing nicely. Sooooo why?

Is it really re-reading the file every couple of seconds? It's a huge file; 14 gig+

Running splunk 4.3.4.

Tags (1)

metalon
New Member

Hi,

Same issue here.
Same error message, on a file that is 4Go+.

Any idea ?

Running splunk 4.3.2

0 Karma
Get Updates on the Splunk Community!

What is the use drop_dm_object_name() clause in a query with tstats.?

I am trying to find out what purpose drop_dm_object_name() serves.

Advisory ID: SVD-2022-0608

Hi,Security alert: Splunk Universal Forwarder.Is this a customer installable upgrade (to version 9), or do I ...

How to use Timechart Query

Hey guys ,I need last 30 days stats for the use-cases that did not fire up on the ES console. Below is the ...