Getting Data In

How do you set the props.conf file to read gz files in Splunk?

ips_mandar
Builder

Hello,

I have gz files on a Windows server that I am monitoring using a universal forwarder and sending it to heavy forwarder --> Indexer
But The data indexed in Splunk is not in a readable format, so may I know what needs to be configured in props.conf to be able to read this data in Splunk?

 [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce]

This type of data comes in Splunk, but I'm unable to read it.

Also, I have another issue of a blocked aeq queue due to which Splunk stopped indexing/sending data and am recieving a warning message as, "Could not send data to output queue (parsingQueue), retrying."

Thanks.

0 Karma

vinod94
Contributor

Hi @ips_mandar,

What type of data you are forwarding?

May be , you can try Splunk Stream app...

https://splunkbase.splunk.com/app/1809/

0 Karma

ips_mandar
Builder

@vinod94 only .gz files I am forwarding and this app won't help

0 Karma

lakshman239
Influencer
0 Karma

ips_mandar
Builder

Thanks @lakshman239
When I tried extracting gz files using 7zip to check file I was seeing [0xbb]F[0xdc]I[0xc5]R[0x84][0xed][0x2][0x85][0x1d][0xf6][0xcd][0x96][0xf7]y[0xf2][0x9]ra[0x97][0xe1][0xe4][0xb8][0xbd][0x95][0xce] in file as well so not sure what could be issue..
Also I have another issue of blocked aeq queue due to which splunk stop indexing/sending data

0 Karma

lakshman239
Influencer

That could also indicate that your 7zip file was not created properly. I don't think splunk supports 7zip, but you could check by taking a simple text file(log file), and 7zip it and upload via GUI on the dev splunk. You can then check the event breaking and props.conf.

regarding blocked queue, you need to check the data flowing from the datasource to indexers to see which all queue are blocked. If the file is huge, it can delay processing and temp the queue can be blocked. But if its persistent, it could indicate config/parsing issues etc..

https://answers.splunk.com/answers/150076/what-is-the-queue-named-aeq-and-how-to-increase-its-max-si...

0 Karma

ips_mandar
Builder

I increased Queue Size to 600MB still it is getting Blocked ..I could see aeq queue is getting blocked

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...