link textHello Experts,
Attached is the sample JSON file which I am trying to upload to Splunk.I have uploaded it by Splunk WEB and it broke the events successfully but when I am trying to upload via CLI it is taking all 8 events into a single event.Can you please help how to break those events(8).
You can use this for your sourcetype definition in props.conf (on Indexer/Heavy forwarder). Do remember to restart/reload splunk instance after making this change.
[ YourSourceType ]
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
LINE_BREAKER=([\r\n]+)\{\"TRL_ID
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%N %z
TIME_PREFIX=TRL_DATETIME_LOCAL_TXN\":\"
MAX_TIMESTAMP_LOOKAHEAD=30
I've used TRL_DATETIME_LOCAL_TXN as the event timestamp field. Change as per your requirement.
Once you've this setup, you can upload a file from CLI like this
splunk add oneshot fullpathtothefiletobeuploaded -index nameofindex -sourcetype sourcetypecreatedabove
Somesh Thank You so much will try this and let you know
Hi vrmandadi,
Try to verify if your role have not the search restrictions and see explanation to monitor this by follow the link:
http://docs.splunk.com/Documentation/Splunk/6.2.1/Security/Addandeditroles
hello ngatchasandra,
The problem is not with roles or permissions it is with the props configurations which need to be done
I have selected the time stamp as auto, when tried using CLI it is taking the file but it is not breaking into events..so can we use the same props from splunk web in the CLI props file
Are you using the correct time-range ( check the timestamp of the events in your file)? What is the retention period of the new index you created and are timestamp of events in your file older than the retention period?
Hello somesh,
I am new to splunk what exactly does retention period mean?
Hey Vineeth,
Please ignore my comments, seems like I posted my comments of some other post here.
You said you're able to successfully update and break events from Splunk Web. so you must've selected some sourcetype for it. Did you use the same sourcetype when you tried to upload it from CLI?? I'm guessing you used splunk add oneshot
method.
what version SPLUNK that use?
version 6.2.3
did you select the indexes when loading the file?
if so, try to post me a sample of your data here, I also try to indexing.
I have attached the sample file,can you please try and let me know the props configuration in CLI..Thanks