March 2018
Beginner to intermediate
576 pages
13h 29m
English
To keep track of what files have been seen before, Splunk stores a checksum of the first 256 bytes of each file it sees. This is usually plenty as most files start with a log message, which is almost guaranteed to be unique. This breaks down when the first 256 bytes are not unique on the same server.
I have seen two cases where this happens, as follows:
================================================================ == Great product version 1.2 brought to you by Great company == == Server kernel version 3.2.1 ==
Read now
Unlock full access