Getting Data In

After upgrading Splunk, why did one of my hosts stop reading files with errors "File too small to check seekcrc" and "Checksum for seekptr didn't match"?

pavanae
Builder

After upgrading Splunk to the latest version, one of my indexers had stopped indexing data and reports the logs below in the splunkd.log.

01-11-2016 18:18:33.289 -0500 INFO WatchedFile - Will begin reading at offset=24997398 for file='/opt/splunkforwarder/var/log/splunk/metrics.log.1'.
01-11-2016 22:44:11.991 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-11-2016 22:44:35.020 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-11-2016 22:47:09.158 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:48:10.467 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:48:10.468 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:50:39.555 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:50:39.556 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:45.301 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 14:10:10.422 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.937 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.938 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.942 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 00:05:37.943 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:15.089 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-13-2016 11:47:32.105 -0500 ERROR TailingProcessor - File will not be read, is too small to match seekptr checksum (file=/opt/jboss/server/21cap/log/console.log). Last time we saw this initcrc, filename was different. You may wish to use a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.
01-13-2016 11:47:37.115 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:55.140 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
0 Karma
1 Solution

vasanthmss
Motivator

Hi Pavanae,

Could you please share the earliest version and the latest version you were upgrading? What are all the components you were updating?

Please check the below URL

http://docs.splunk.com/Documentation/Splunk/6.3.1/Installation/Aboutupgradingto6.3READTHISFIRST

Thanks,
V

V
0 Karma

pavanae
Builder

Earliest version :- 6.1.3
Latest version :- 6.3.2

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...