Splunk Search

need help with uploading a directory of .txt file

jonzhong
New Member

previously, i tried uploading a directory of .txt file and it was able to read the content of all the .txt file
however, out of no reason, when i try to upload another directory of .txt file, it is only able to read the file name.
what is wrong?

Tags (1)
0 Karma

markthompson
Builder

There are a variety of reasons for this,
Firstly ensure that your splunk has access to the directories
Secondly, go through the process one step at a time, double checking you're adding everything.

Make sure you set it up as continuous as well.

If you need further help, let me know.

Don't forget to mark this as answer if this works!

0 Karma

jonzhong
New Member

i try to delete the datas, remove the directory that i last added.
when i try to add the directory back again, somehow i am unable to view it, but when i manage inputs, it did shows that splunk has added the directory. why is this so?

0 Karma

markthompson
Builder

Did you set it up as having a specific host?
Try running index=* and see if it pops up with any of your events

0 Karma

jonzhong
New Member

i did try uploading indexes individually and there is not issue with that.

0 Karma

markthompson
Builder

Are your events inside of that search? for * ?
If so, click on their host and it should narrow it down for you.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...