Getting Data In

Can't index a .csv file?!?

Jochen_1987
Explorer

Hey,
I tried to index a .csv file several times and I can see the file in
"Manager » Data inputs » Files & directories" but I can't find it?!?!
I tried a different file and directory and there was the same result...
I can also see all indexes due to the settings of "Access controls » Roles".
To make a long story short I have no idea why i can't find the files that are indexed....

Tags (2)
1 Solution

MuS
Legend

Hi Jochen

is your input index into another then the default index?

if so, do you search the correct index?

what does splunkd.log report?

have you searched index=_internal for the file in question?

cheers,

MuS

View solution in original post

proletariat99
Communicator

same problem here. I've put it in default, main, created my own new index, given it default sourcetypes and custom sourcetypes and it just doesn't appear anywhere.

Never indexed, never uploaded, as far as I can tell. What gives?

0 Karma

MuS
Legend

Hi Jochen

is your input index into another then the default index?

if so, do you search the correct index?

what does splunkd.log report?

have you searched index=_internal for the file in question?

cheers,

MuS

Jochen_1987
Explorer

ok, now I now why it doesn't work, but how do i get the data back in splunk:-)?

0 Karma

Ayn
Legend

That could very well be the problem. Splunk keeps track of how far into the file it has read. If you delete the file and reupload it, it will not be reindexed. Some more information is available here: http://docs.splunk.com/Documentation/Splunk/latest/Data/Howlogfilerotationishandled

0 Karma

MuS
Legend

okay, splunk will not index this file again in this case.
just make sure there is no permission problem and the path is accessible for splunk, then it should be fine. do you use any regex for this input and props/transforms as well?
could you post the stanza from inputs.conf?

0 Karma

Jochen_1987
Explorer

no result... the thing is I already indexed the file a few days ago but then deleted it... could that be the problem? and if i want to upload a file that's fine, i just got problems if i want to monitor a file/directory...

0 Karma

ryantzj
Explorer

Having a very similar problem on my side, May i know what you did to resolve this.

0 Karma

MuS
Legend
0 Karma

MuS
Legend

it could also be a permission problem, meaning the user splunk is running is not allowed to read the file.
try searching for the file name in index=_internal instead of path name.

0 Karma

Jochen_1987
Explorer

Hi,
Input index is default index... Splunkd.log reports "TailingProcessor - Parsing configuration stanza: monitor:C:..." and I searched index=_internal and then the path of the file but there were no results..

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...