<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ingest Jan month data into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642295#M109463</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242456"&gt;@Anud&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that the 4 GB of data aren't in the same file!&lt;/P&gt;&lt;P&gt;Anyway, you have to follow the normal procedure to ingest csv files documented at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/Monitorfilesanddirectorieswithinputs.conf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are many video (e.g.&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=3kx0OGKy_XU" target="_blank"&gt;https://www.youtube.com/watch?v=3kx0OGKy_XU&lt;/A&gt;) that describes this process.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 12:42:02 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-05-04T12:42:02Z</dc:date>
    <item>
      <title>How to ingest Jan month data into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642288#M109460</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;Please suggest me to ingest the Jan month data into Splunk.&lt;BR /&gt;Those files are CSV files and its contains 18gb size and total 4 days data has to sent to Splunk index.&lt;BR /&gt;please let us know the possibilities to ingest old data.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 12:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642288#M109460</guid>
      <dc:creator>Anud</dc:creator>
      <dc:date>2023-05-04T12:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Jan month data into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642295#M109463</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242456"&gt;@Anud&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that the 4 GB of data aren't in the same file!&lt;/P&gt;&lt;P&gt;Anyway, you have to follow the normal procedure to ingest csv files documented at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/Monitorfilesanddirectorieswithinputs.conf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are many video (e.g.&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=3kx0OGKy_XU" target="_blank"&gt;https://www.youtube.com/watch?v=3kx0OGKy_XU&lt;/A&gt;) that describes this process.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 12:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642295#M109463</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-05-04T12:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Jan month data into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642297#M109464</link>
      <description>Thanks for the quick response!! Here each day we have 18GB file size, so is it possible for normal process way to ingest. That data is from Jan month and indexed time stamp will be today date or else Jan month. how it looks, please let us know.</description>
      <pubDate>Thu, 04 May 2023 13:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642297#M109464</guid>
      <dc:creator>Anud</dc:creator>
      <dc:date>2023-05-04T13:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest Jan month data into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642299#M109465</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242456"&gt;@Anud&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure that's possible to read a 18GB csv file!&lt;/P&gt;&lt;P&gt;And it's also difficoult to manage a file of thst dimensions, I hint to find a different way to write tis file, e.g. applying a rotation policy.&lt;/P&gt;&lt;P&gt;Anyway, if possible, you can assign the timestamp based on one field in csv as usual.&lt;/P&gt;&lt;P&gt;If you don't have a date/time field in the csv how you define which rows must be indexed with the today's date and which one with the last month?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 13:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-Jan-month-data-into-Splunk/m-p/642299#M109465</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-05-04T13:29:14Z</dc:date>
    </item>
  </channel>
</rss>

