Getting Data In

After upgrading Splunk, why did one of my hosts stop reading files with errors "File too small to check seekcrc" and "Checksum for seekptr didn't match"?

pavanae
Builder

After upgrading Splunk to the latest version, one of my indexers had stopped indexing data and reports the logs below in the splunkd.log.

01-11-2016 18:18:33.289 -0500 INFO WatchedFile - Will begin reading at offset=24997398 for file='/opt/splunkforwarder/var/log/splunk/metrics.log.1'.
01-11-2016 22:44:11.991 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-11-2016 22:44:35.020 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-11-2016 22:47:09.158 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:48:10.467 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:48:10.468 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 00:50:39.555 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 00:50:39.556 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:23.273 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/console.log'.
01-12-2016 14:07:45.301 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-12-2016 14:10:10.422 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.937 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.938 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/21cap/log/server.log'.
01-13-2016 00:05:37.942 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 00:05:37.943 -0500 INFO WatchedFile - Will begin reading at offset=0 for file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:15.089 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/20cap/log/console.log'.
01-13-2016 11:47:32.105 -0500 ERROR TailingProcessor - File will not be read, is too small to match seekptr checksum (file=/opt/jboss/server/21cap/log/console.log). Last time we saw this initcrc, filename was different. You may wish to use a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.
01-13-2016 11:47:37.115 -0500 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/jboss/server/20cap/log/server.log'.
01-13-2016 11:47:55.140 -0500 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/opt/jboss/server/21cap/log/server.log'.
0 Karma
1 Solution

vasanthmss
Motivator

Hi Pavanae,

Could you please share the earliest version and the latest version you were upgrading? What are all the components you were updating?

Please check the below URL

http://docs.splunk.com/Documentation/Splunk/6.3.1/Installation/Aboutupgradingto6.3READTHISFIRST

Thanks,
V

V
0 Karma

pavanae
Builder

Earliest version :- 6.1.3
Latest version :- 6.3.2

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...