Getting Data In

Uploaded files not indexed

mcomfurf
Path Finder

I'm trying to manually upload some text files, with a .txt extension, to Splunk. I went through the UI to Upload and index a file, and Splunk indicates that it has successfully indexed it, but the file cannot be found in searches.
Any advice as to what I might do differently or troubleshooting steps would be lovely.

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi mcomfurf,

here are some typical troubleshooting tips:

  • Do you search the correct time range - try all time?
  • Do you search the correct index - try index=main which is the default or what ever index name you have?
  • Do you have permission to search this index?
  • search index=_internal source=*splunkd.log on the indexer for any error related to the this txt file

hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi mcomfurf,

here are some typical troubleshooting tips:

  • Do you search the correct time range - try all time?
  • Do you search the correct index - try index=main which is the default or what ever index name you have?
  • Do you have permission to search this index?
  • search index=_internal source=*splunkd.log on the indexer for any error related to the this txt file

hope this helps ...

cheers, MuS

mcomfurf
Path Finder

Thanks, MuS, that was just the ticket. The text files were binary & couldn't be processed after ingestion. Too bad the Splunk UI does not warn you of this when you upload the file.

0 Karma

mcomfurf
Path Finder

I've tried searching for the file name as source, and for the sourcetype assigned to it.

0 Karma

lguinn2
Legend

What have you tried in searches?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...