This is not because "crc".
I takes the contents, I insert it in another file, I put the same name file in the directory and Hop, Splunk takes.
It's really weird because, as I say, with another file, Splunk takes the file and when I query, I found data !!!!
Sorry, I have 6 files in the folder (not 5):
DcServerX_eventlogs_application.CSV
DcServerXeventlogs_DS.csv
DcServerXeventlogs_FRS.csv
DcerverXeventlogs_security.csv
DcServerXeventlogs_system.csv
And the file DcServerX_eventlogs_DNS.csv
This is the file that causes me problems sometimes and I do not know why.
My Inputs.conf is (fonctional for 5 files??):
[monitor://D:SplunkDataInputTI-WINEVENTS-RNI.csv]
index = TI-WINEVENTS-RNI
host_segment = 3
What do you think for solution?
.
.
.
Here's a search (Newest to oldest) :
.
.
04/02/15 04:17:39,455
02-04-2015 04:17:39.455 +0000 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='D:/SplunkDataInput/TI-WINEVENTS-RNI/BLABLABLA_eventlogs_DNS.csv'.
host = TOTO source = C:\Program Files/SplunkUniversalForwarder/var/log/splunk/splunkd.log sourcetype = splunkd
.
.
03/02/15 04:15:58,401
02-03-2015 04:15:58.401 +0000 INFO WatchedFile - Will begin reading at offset=0 for file='D:\SplunkDataInput\TI-WINEVENTS-RNI\BLABLABLA_eventlogs_DNS.csv'.
host = TOTO source = C:/Program Files/SplunkUniversalForwarder/var/log/splunk/splunkd.log sourcetype = splunkd
.
.
03/02/15 04:15:58,401
02-03-2015 04:15:58.401 +0000 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='D:/SplunkDataInput/TI-WINEVENTS-RNI/BLABLABLAeventlogs_DNS.csv'.
host = TOTO source = C:/Program Files/SplunkUniversalForwarder/var/log/splunk/splunkd.log sourcetype = splunkd
.
.
02/02/15 04:15:18,748
02-02-2015 04:15:18.748 +0000 INFO WatchedFile - Will begin reading at offset=0 for file='D:/SplunkDataInput/TI-WINEVENTS-RNI/BLABLABLA_eventlogs_DNS.csv'.
host = TOTO source = C:/Program Files/SplunkUniversalForwarder/var/log/splunk/splunkd.log sourcetype = splunkd
.
.
... View more