After upgrading Splunk to the latest version, one of my indexers had stopped indexing data and reports the logs below in the splunkd.log.
01-11-2016 18:18:33.289 -0500 INFO WatchedFile - Will begin reading at offset=24997398 for file='/opt/splunkforwarder/var/log/splunk/metrics.log.1'.
01-11-2016 22:44:11.991 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-11-2016 22:44:35.020 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-11-2016 22:47:09.158 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:48:10.467 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:48:10.468 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:50:39.555 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:50:39.556 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:45.301 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 14:10:10.422 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.937 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.938 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.942 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 00:05:37.943 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:15.089 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-13-2016 11:47:32.105 -0500 ERROR TailingProcessor - File will not be read, is too small to match seekptr checksum (file=/opt/jboss/server/21cap/log/console.log). Last time we saw this initcrc, filename was different. You may wish to use a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.
01-13-2016 11:47:37.115 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:55.140 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
Hi Pavanae,
Could you please share the earliest version and the latest version you were upgrading? What are all the components you were updating?
Please check the below URL
http://docs.splunk.com/Documentation/Splunk/6.3.1/Installation/Aboutupgradingto6.3READTHISFIRST
Thanks,
V
Earliest version :- 6.1.3
Latest version :- 6.3.2