Getting Data In

Files not being Indexed

ShaneNewman
Motivator

We have files that are not being indexed, yet they are seen by Splunk. We have 38 files FTP'ed to a file folder which Splunk monitors every hour. Each hour, the previous 24 hours worth of data is dumped, just in case the job does not run as expected, this keeps us from having data loss. Being this way, we know that Splunk sees the old data as duplicate data, so we use this config to solve it:

[monitor://E:\inetpub\ftproot\NPR\PROD] 
sourcetype = meditech_npr 
index = capsule_npr 
crcSalt = <SOURCE> 

Until the upgrade to Splunk 6/6.0.1, this has worked fine, it no longer appears to work though. It is of extreme importance that this issue is resolved immediately. Currently, I am having to delete the entire _thefishbucket index every few hours to ensure that data is getting indexed properly.

Any help would be greatly appreciated!

0 Karma
1 Solution

ShaneNewman
Motivator

This is the message I got back from Splunk Support.

It looks like this behavior has been identified as bug SPL-76980 and a code change has already been made that should resolved the issue, being included tentatively in version 6.0.2.

View solution in original post

0 Karma

ShaneNewman
Motivator

This is the message I got back from Splunk Support.

It looks like this behavior has been identified as bug SPL-76980 and a code change has already been made that should resolved the issue, being included tentatively in version 6.0.2.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...