Monitoring Splunk

How to open the .tsidx file

muthukrishnan
New Member

I seen several file is shown .tsidx under the C:\Program Files\Splunk folder.
I want to know how to open that file.

Tags (1)
0 Karma
1 Solution

MHibbin
Influencer

Hi,

I'm not sure how to open the files, they are used for Splunk indexing and as such it probably isn't wise to edit the file/archive.

The following Splunk documentation mentions some commands which may be of use... HOWEVER YOU SHOULD TAKE NOTE OF THE WARNING... "Caution: Do not use these commands without consulting Splunk Support first." which is noted at the beginning of the text.

If you are looking to clean event data out of the index you could use the CLI clean command detailed here, again take note... once the event data has been removed you can not restore unless you have the original stored.

Regards,

MHibbin

View solution in original post

piebob
Splunk Employee
Splunk Employee

you can't open the files yourself, but you can use the tsidxprobe tool to have Splunk review them for you. check out:
http://docs.splunk.com/Documentation/Splunk/5.0.3/Troubleshooting/CommandlinetoolsforusewithSupport#...

for more info.

MHibbin
Influencer

Hi,

I'm not sure how to open the files, they are used for Splunk indexing and as such it probably isn't wise to edit the file/archive.

The following Splunk documentation mentions some commands which may be of use... HOWEVER YOU SHOULD TAKE NOTE OF THE WARNING... "Caution: Do not use these commands without consulting Splunk Support first." which is noted at the beginning of the text.

If you are looking to clean event data out of the index you could use the CLI clean command detailed here, again take note... once the event data has been removed you can not restore unless you have the original stored.

Regards,

MHibbin

MHibbin
Influencer

If this helped answer you question, can you please mark the answer as accepted.

0 Karma

muthukrishnan
New Member

Thanks MHibbin

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Yes, these are Splunk's internal data format. Trying to open/edit them is very unwise.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...