Technitium DNS Splunk Add-on Updated to v0.1.1

Written by

on

in

,

I have revised my Technitium DNS Add-on to fix a problem with ingestion of JSON logs. I also updated and added some refreshes to the dashboard.

I noticed some unusual reporting on the dashboard yesterday and discovered that the dns.json file was sometimes being ignored. Splunk was reporting an error monitoring the file:

ERROR TailReader [1423568 tailreader0] - File will not be read, seekptr checksum did not match (file=/var/log/technitium/dns/dns.json). Last time we saw this initcrc, filename was different. You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source. Consult the documentation or file a support case online at http://www.splunk.com/page/submit_issue for more info.

I increased the initCrcLength to 2048 and the problem was solved. Installing this update will cause all of the log files to be re-ingested, so if you have v0.1.0 installed, you will want to move any ingested log files somewhere else before pushing this update to your forwarder.

The dashboard was updated to do refreshes at 2-minute intervals. Not all the panels were refreshing, so I added refreshes where necessary.

The add-on has been updated on Splunkbase.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *