Splunk Search

Creating local temporary file creates Checksum mismatch

Epicism1
Explorer

Hello,

I'm trying to create an app that runs a script that executes an app, and the app creates a log file that I'm trying to index. The issue is that when I write the log file to a folder in the app I'm getting a Checksum mismatch, which is causing issues. I don't want to use the OS' temporary folder because it needs to be OS neutral (and TMK inputs.conf doesn't allow for %TEMP% type variables), so is there a way to create temporary files within the Splunk directory that are not included in the Checksum verification?

Thank you.

0 Karma
1 Solution

guilmxm
Influencer

Hi,

I would use $SPLUNK_HOME/var/log/

This won't generate the checksum message.

View solution in original post

0 Karma

guilmxm
Influencer

Hi,

I would use $SPLUNK_HOME/var/log/

This won't generate the checksum message.

0 Karma

Epicism1
Explorer

Brilliant!

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...