This is my first post in here. I have installed Splunk Light a few weeks ago and have been using it for reporting on various applications logs.
Today I deployed a few scripts that copy log files to my splunk server which is monitoring the folder and reading the logs.
Now, if a file is copied twice (or more) to the folder, Splunk Light reindexes it and duplicates the data.
I read about it and notice my _thefishbucket was empty no matter what. So i decided that it was because is was the Light version and uninstalled it and reinstalled Splunk but now the Enterprise version.
Still my _thefishbucket index still empty (0 events).
I dont know what to do to turn on the cyclic redundancy checks and it is killing the proposition of using Splunk for logs reporting.
So my questions are: how do I switch it on? and shouldn't it work by default?
Thanks in advance for your help,
... View more