Hello Splunkers,
I have an issue where Splunk some times skips to index the log file during the rotation or delays the indexing during the log rotation.
This issue is only for specific file.So we can rule out the blocked queue, timezone, network throughput or slow performing indexer/forwarder.
Sar report showed good iostat cpu and mem stats on the forwarder.
I don't see initcrclength(crcSalT) or file_descriptor related issue in the splunk log.
In fact there are no error in the splunk log during this issue.
Any guidance is highly appreciated.
Best Regards,
Ankith
↧