Splunk Search

Splunk skipping indexing of Websphere logs

asherinb
Explorer

We have a case where 4 log files are being monitored.
Daily the log file is rolled to a back up and truncated at the end of the day.

[monitor:///projects/Agent/runtime/logs/websphere1.log]
index=nss
sourcetype=NSS
[monitor:///projects/Agent/runtime/logs/websphere2.log]
index=rts
sourcetype=NSS
[monitor:///projects/Agent/runtime/logs/websphere3.log]
index=nss
sourcetype=NSS
[monitor:///projects/Agent/runtime/logs/websphere4.log]
index=nss

One file or the other gest skipped daily as the data appears same to Splunk.

I tried changing intCRClength to a higher value (around 750 bytes) but that doesnt seem to help either.

Please help in fixing this issue.

Thanks in advance

0 Karma
1 Solution

jeremiahc4
Builder

Have you tried adding crcSalt= to your inputs.conf?

View solution in original post

jeremiahc4
Builder

Have you tried adding crcSalt= to your inputs.conf?

asherinb
Explorer

thanks, adding crcsalt= worked

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...