Splunk Search

Splunk skipping indexing of Websphere logs

asherinb
Explorer

We have a case where 4 log files are being monitored.
Daily the log file is rolled to a back up and truncated at the end of the day.

[monitor:///projects/Agent/runtime/logs/websphere1.log]
index=nss
sourcetype=NSS
[monitor:///projects/Agent/runtime/logs/websphere2.log]
index=rts
sourcetype=NSS
[monitor:///projects/Agent/runtime/logs/websphere3.log]
index=nss
sourcetype=NSS
[monitor:///projects/Agent/runtime/logs/websphere4.log]
index=nss

One file or the other gest skipped daily as the data appears same to Splunk.

I tried changing intCRClength to a higher value (around 750 bytes) but that doesnt seem to help either.

Please help in fixing this issue.

Thanks in advance

0 Karma
1 Solution

jeremiahc4
Builder

Have you tried adding crcSalt= to your inputs.conf?

View solution in original post

jeremiahc4
Builder

Have you tried adding crcSalt= to your inputs.conf?

asherinb
Explorer

thanks, adding crcsalt= worked

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...