splunk / splunk-shuttl

Splunk app for archive management, including HDFS support.
Apache License 2.0
36 stars 19 forks source link

Restart splunk #128

Open chunmingpoxiao opened 11 years ago

chunmingpoxiao commented 11 years ago

df..when i restart splunk,i can't see buckets moved into HDFS.

chunmingpoxiao commented 11 years ago

i can't see other buckets

petterik commented 11 years ago

@chunmingpoxiao see the comment here: https://github.com/splunk/splunk-shuttl/issues/63#issuecomment-16532322

I'm assuming that's your problem, since it seems like your configuration is correct because you have some buckets in HDFS. Freeze more buckets and you should eventually see everything in HDFS.

Can you explain what you mean by "I cant' see other buckets"?

chunmingpoxiao commented 11 years ago

QQ 20130418115203..... i try again,Shuttl transfers a bucket but not transfer all the buckets in "safe-bucket" directory...lost 0,1,2,4,6 CSV 。。it never transfer all the buckets in the "safe-buckets" directory to HDFS.

petterik commented 11 years ago

See if you can find anything in the logs at $SPLUNK_HOME/var/logs/splunk/shuttl.log. You might be able to find out what happened to bucket 0, 1, 2, 4 and 6. This is strange behavior. I've never seen it before.

chunmingpoxiao commented 11 years ago

@petterik can i set the field of the csv file.......you says:SpIF has the following fields:_time ,source ,host ,sourcetype,_raw,_meta .??...

chunmingpoxiao commented 11 years ago

@petterik
QQ 20130426093952 what cause this error?