[monitor:///home/paul/training_status/]
whitelist = (\.csv$|\.CSV$)
blacklist = \.filepart$
index=training_index
sourcetype=training_status
crcSalt = <SOURCE>
The file gets updated once per week. In many cases, the file is not being fully consumed. The most recent update missed 19 records (which were consumed the last time the file was updated )
Splunkd.log shows:
04-06-2017 07:39:19.584 -0700 INFO WatchedFile - Will begin reading at offset=4234 for file='/home/paul/training_status/filename.csv
So, my uneducated guess would be that splunkd is seeing data that it's already consumed and thus ignoring those 19 records before it starts ingesting.
How do I prevent this? I thought setting crcSalt=<SOURCE> was supposed to handle this.
Thank you.
↧