Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

CSV Monitoring issues

$
0
0
[monitor:///home/paul/training_status/] whitelist = (\.csv$|\.CSV$) blacklist = \.filepart$ index=training_index sourcetype=training_status crcSalt = &ltSOURCE&gt The file gets updated once per week. In many cases, the file is not being fully consumed. The most recent update missed 19 records (which were consumed the last time the file was updated ) Splunkd.log shows: 04-06-2017 07:39:19.584 -0700 INFO WatchedFile - Will begin reading at offset=4234 for file='/home/paul/training_status/filename.csv So, my uneducated guess would be that splunkd is seeing data that it's already consumed and thus ignoring those 19 records before it starts ingesting. How do I prevent this? I thought setting crcSalt=&ltSOURCE&gt was supposed to handle this. Thank you.

Viewing all articles
Browse latest Browse all 1551

Trending Articles