<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Small CSV file indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612880#M106040</link>
    <description>&lt;P&gt;&amp;nbsp;just notices that if I add data manually from the HF itself the data is not indexed also&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what can be the reason&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Sep 2022 12:31:02 GMT</pubDate>
    <dc:creator>rayar</dc:creator>
    <dc:date>2022-09-13T12:31:02Z</dc:date>
    <item>
      <title>Help with small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612859#M106035</link>
      <description>&lt;P&gt;I am trying to index a small CSV file with 2 columns and Size -5.32 KB (5,453 bytes) , Size on Disk&amp;nbsp; -&amp;nbsp;8.00 KB (8,192 bytes) by Heavy Forwarder&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on the forwarder I see that shows 0 files&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rayar_0-1663067516887.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21432i51C4B0DD33E5FC65/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rayar_0-1663067516887.png" alt="rayar_0-1663067516887.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;inputs.conf&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[monitor://\\ntnet\filestore1\information_security$\ACSC_Websense_Large_Web_Traffic_Exclusion_List\]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = websense_large_web_traffic&lt;BR /&gt;sourcetype = csv&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;initCrcLength = 512&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 13:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612859#M106035</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-13T13:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612869#M106036</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;have you data in Splunk (using a search)?&lt;/P&gt;&lt;P&gt;the dashboard of your screenshot isn't relevant, see in the search dashboard of the Search Head.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 11:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612869#M106036</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T11:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612875#M106037</link>
      <description>&lt;P&gt;the data is not indexed&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also don't see any activities in index=_*&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the issue that I see that the HF see 0 files under the path&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 12:04:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612875#M106037</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-13T12:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612876#M106038</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to search something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=websense_large_web_traffic source="*\&amp;lt;your_file_name&amp;gt;"&lt;/LI-CODE&gt;&lt;P&gt;not in _* indexes.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 12:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612876#M106038</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T12:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612877#M106039</link>
      <description>&lt;P&gt;the data is not indexed to the index&amp;nbsp;&lt;/P&gt;&lt;P&gt;also I don't see any events in the internal indexes&amp;nbsp;&lt;/P&gt;&lt;P&gt;what can be the reason HF doesn't recognize filers&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;I copied the same file to my local and was able to index manually&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 12:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612877#M106039</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-13T12:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612880#M106040</link>
      <description>&lt;P&gt;&amp;nbsp;just notices that if I add data manually from the HF itself the data is not indexed also&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what can be the reason&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 12:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612880#M106040</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-13T12:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612881#M106041</link>
      <description>&lt;P&gt;i&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maybe the filename is missing, please try to use in your inputs.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://\\ntnet\filestore1\information_security$\ACSC_Websense_Large_Web_Traffic_Exclusion_List\*.csv]&lt;/LI-CODE&gt;&lt;P&gt;or adding at the end of the path the filename with extension.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 12:35:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612881#M106041</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T12:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612910#M106048</link>
      <description>&lt;P&gt;[monitor://\\ntnet\filestore1\information_security$\ACSC_Websense_Large_Web_Traffic_Exclusion_List\*.csv]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = websense_large_web_traffic&lt;BR /&gt;sourcetype = csv&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;initCrcLength = 512&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;still I see 0 in the heavy forwarder&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rayar_0-1663083308628.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21438iD2BD152FD6B08A24/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rayar_0-1663083308628.png" alt="rayar_0-1663083308628.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 15:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612910#M106048</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-13T15:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612911#M106049</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is a network folder, have the user you're using grants to access this folder?&lt;/P&gt;&lt;P&gt;if you run in a cmd window&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;dir \\ntnet\filestore1\information_security$\ACSC_Websense_Large_Web_Traffic_Exclusion_List\*.csv&lt;/LI-CODE&gt;&lt;P&gt;have you results?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 15:39:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612911#M106049</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-13T15:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612912#M106050</link>
      <description>&lt;P&gt;C:\Users\issplunk&amp;gt;dir \\ntnet\filestore1\information_security$\ACSC_Websense_Large_Web_Traffic_Exclusion_List\*.csv&lt;BR /&gt;Volume in drive \\ntnet\filestore1 is SCCM Content&lt;BR /&gt;Volume Serial Number is 1EFA-6F4C&lt;/P&gt;&lt;P&gt;Directory of \\ntnet\filestore1\information_security$\ACSC_Websense_Large_Web_Traffic_Exclusion_List&lt;/P&gt;&lt;P&gt;09/12/2022 04:01 PM 5,453 Websense_Lare_Web_Traffic_Exclusion_August_2022.csv&lt;BR /&gt;09/13/2022 03:23 PM 5,458 Websense_Lare_Web_Traffic_Exclusion_082022.csv&lt;BR /&gt;2 File(s) 10,911 bytes&lt;BR /&gt;0 Dir(s) 211,867,983,872 bytes free&lt;/P&gt;&lt;P&gt;C:\Users\issplunk&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 15:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/612912#M106050</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-13T15:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613012#M106064</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please run this last try:&lt;/P&gt;&lt;P&gt;change the name of your file and see if now it's indexed, because Splunk doesn't index a file twice, the only way to do this is using crcSalt and changing a filename.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 06:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613012#M106064</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-14T06:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613030#M106070</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;I already tried it before and it still shows 0 files&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 08:27:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613030#M106070</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-14T08:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613032#M106071</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;last try,&lt;/P&gt;&lt;P&gt;could you try to copy your file in a folder without "$" in the path, changing the input stanza to the new folder?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 08:32:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613032#M106071</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-14T08:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613171#M106103</link>
      <description>&lt;P&gt;I moved the monitoring to Linux UF and it resolved the issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 05:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613171#M106103</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-09-15T05:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Small CSV file indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613181#M106104</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/45236"&gt;@rayar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's always a good idea!&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 07:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-with-small-CSV-file-indexing/m-p/613181#M106104</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-15T07:33:22Z</dc:date>
    </item>
  </channel>
</rss>

