Hello,
we have issue reindexing archives as gz files even using crcSalt = <SOURCE> or crcSalt = REINDEXMPLEASE
We CAN'T go on each UF and clean fishbucket.
UF (V7.1.4) linux splunkd.log :
07-19-2022 18:19:09.129 +0200 INFO ArchiveProcessor - Handling file=/var/log/MAJ-OS.log-20220601.gz
07-19-2022 18:19:09.130 +0200 INFO ArchiveProcessor - reading path=/var/log/MAJ-OS.log-20220601.gz (seek=0 len=1356)
07-19-2022 18:19:09.281 +0200 INFO ArchiveProcessor - Archive with path="/var/log/MAJ-OS.log-20220601.gz" was already indexed as a non-archive, skipping.
07-19-2022 18:19:09.281 +0200 INFO ArchiveProcessor - Finished processing file '/var/log/MAJ-OS.log-20220601.gz', removing from stats
It also says "new tailer already processed path..."
inputs.conf app from deployment-apps (V8.2.2) :
[monitor:///var/log/MAJ-OS.log*]
blacklist = archives
disabled = false
index = inf-servers
sourcetype = MAJ-OS
crcSalt = <SOURCE>
Thanks for your help.
Solved with support help:
add:
crcSalt = <SOURCE>
initCrcLength = 1000
ignoreOlderThan = 90d
---
Another personal workaround that could do the job : example :
[script://./bin/MAJ-OS_zcat.sh]
source = MAJ-OS_zcat
interval = 2592000
disabled = true
index = inf-servers
sourcetype = MAJ-OS
MAJ-OS_zcat.sh :
#!/bin/sh
content=`zcat /var/log/MAJ-OS.log-20220701.gz | grep -i status`
echo $content "(catchup 07/20/2022)"
🙂
Solved with support help:
add:
crcSalt = <SOURCE>
initCrcLength = 1000
ignoreOlderThan = 90d
---
Another personal workaround that could do the job : example :
[script://./bin/MAJ-OS_zcat.sh]
source = MAJ-OS_zcat
interval = 2592000
disabled = true
index = inf-servers
sourcetype = MAJ-OS
MAJ-OS_zcat.sh :
#!/bin/sh
content=`zcat /var/log/MAJ-OS.log-20220701.gz | grep -i status`
echo $content "(catchup 07/20/2022)"
🙂