<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: importing all the files available in a directory in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83589#M17380</link>
    <description>&lt;P&gt;[monitor:://c:\Test\New_Folder\USB_Data]&lt;BR /&gt;
index = usb_data&lt;BR /&gt;
sourcetype = USB&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:35:46 GMT</pubDate>
    <dc:creator>abhayneilam</dc:creator>
    <dc:date>2020-09-28T12:35:46Z</dc:date>
    <item>
      <title>importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83579#M17370</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Can any body tell me how to import all the files of a particular directory in splunk at one go ?&lt;BR /&gt;
next time if I keep any other file in the same directory it should be automatically imported in the splunk, no need to import it manually..&lt;/P&gt;

&lt;P&gt;Kindly get me the solution asap, as I am in urgent need of this..&lt;/P&gt;

&lt;P&gt;Thanks in Advance,&lt;BR /&gt;
Abhay&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 13:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83579#M17370</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2012-10-08T13:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83580#M17371</link>
      <description>&lt;P&gt;Look at the docs here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/UseSplunkWeb"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/UseSplunkWeb&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You'll want -&amp;gt; Continuously index data from a file or directory this Splunk instance can access&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 13:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83580#M17371</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-08T13:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83581#M17372</link>
      <description>&lt;P&gt;I am going to this option and giving the input as following : &lt;/P&gt;

&lt;P&gt;D:\TEST&lt;/P&gt;

&lt;P&gt;and clicking on SAVE button..&lt;/P&gt;

&lt;P&gt;In this case only the first file in TEST directory is taking.. other file it is not taking..&lt;/P&gt;

&lt;P&gt;Please suggest !!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 13:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83581#M17372</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2012-10-08T13:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83582#M17373</link>
      <description>&lt;P&gt;I am going to this option and giving the input as following : D:\TESTand clicking on SAVE button..In this case only the first file in TEST directory is taking.. other file it is not taking..Please suggest !!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 14:49:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83582#M17373</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2012-10-08T14:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83583#M17374</link>
      <description>&lt;P&gt;What type of file is it that's not getting picked up from that directory?  What is the size of the file?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 16:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83583#M17374</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-08T16:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83584#M17375</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This is a file which is "|" separated which contains 14 columns. The first line is header and rest of the lines are the values. I have five files in a directory: 104KB, 18KB, 69KB, 63KB and 8KB size of files...It is taking only the first file..please suggest how to get this task done...&lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;BR /&gt;
Abhay&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 04:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83584#M17375</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2012-10-09T04:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83585#M17376</link>
      <description>&lt;P&gt;I am using a trial version ? Is there any limitation for this ?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 07:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83585#M17376</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2012-10-09T07:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83586#M17377</link>
      <description>&lt;P&gt;Trial version is not the problem.  Can you post the inputs.conf settings in:&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/etc/system/local/&lt;/P&gt;

&lt;P&gt;You can see the settings and options for file monitoring here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 12:14:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83586#M17377</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-09T12:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83587#M17378</link>
      <description>&lt;P&gt;I have not written any thing in the inputs.conf..kindly suggest me what to write ? but i was clicking on "Continuously index data from a file or directory this Splunk instance can access" this optioin while importing the entire directory. I am giving my directory name as c:\Test\New_Folder\USB_Data&lt;/P&gt;

&lt;P&gt;I have created an Index manuaally called "usb_data" and creating source type at the time of importing data manually.. Kindly suggest me how it can be done through configuration file or through any other way...&lt;/P&gt;

&lt;P&gt;Please Help !!&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Abhay&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83587#M17378</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2020-09-28T12:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83588#M17379</link>
      <description>&lt;P&gt;Look in the directory in my comment and look at the inputs.conf file that was created for you.  Post the stanza in your question&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 18:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83588#M17379</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-09T18:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83589#M17380</link>
      <description>&lt;P&gt;[monitor:://c:\Test\New_Folder\USB_Data]&lt;BR /&gt;
index = usb_data&lt;BR /&gt;
sourcetype = USB&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:35:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83589#M17380</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2020-09-28T12:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83590#M17381</link>
      <description>&lt;P&gt;Change the file to this and restart Splunk.  I assume the index has been properly created? &lt;/P&gt;

&lt;P&gt;[monitor:://c:\Test\New_Folder\USB_Data] &lt;BR /&gt;
disabled=0&lt;BR /&gt;
crcSalt=&lt;SOURCE&gt; &lt;BR /&gt;
index = usb_data &lt;BR /&gt;
sourcetype = USB&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;--&amp;gt;(the word source should be in caps)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:35:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83590#M17381</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2020-09-28T12:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83591#M17382</link>
      <description>&lt;P&gt;you meand to say crcSalt=&lt;SOURCE&gt;&lt;BR /&gt;
         or&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;SOURCEtype = USB&lt;/P&gt;

&lt;P&gt;and Do I need to configure props.conf for this also ? &lt;/P&gt;

&lt;P&gt;please suggest !!&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Abhay&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 18:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83591#M17382</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2012-10-09T18:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83592#M17383</link>
      <description>&lt;P&gt;First one...yes.  Nothing in props.conf&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 18:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83592#M17383</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-09T18:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83593#M17384</link>
      <description>&lt;P&gt;I am trying to extract the fields of my files : &lt;/P&gt;

&lt;P&gt;I have two files which is of same type means : file_one contains: name|age|sex|location&lt;BR /&gt;
xyz|45|M|kol&lt;BR /&gt;
mno|50|F|mum&lt;/P&gt;

&lt;P&gt;and file_two contains:&lt;BR /&gt;
name|age|sex|location&lt;BR /&gt;
abc|60|M|hyd&lt;BR /&gt;
lkg|100|M|ker&lt;/P&gt;

&lt;P&gt;these two files are in the same directory, and I am extracting the fields: name age sex location by the following method:&lt;/P&gt;

&lt;P&gt;index="usb_data" | extract transform_usb_data &lt;/P&gt;

&lt;P&gt;when I am giving this I am getting all the fields are getting extracted but can you suggest me how to automated this process from transfoms.conf file&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83593#M17384</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2020-09-28T12:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83594#M17385</link>
      <description>&lt;P&gt;my transforms.conf contains :&lt;/P&gt;

&lt;P&gt;[transform_usb_data]&lt;BR /&gt;
delims = "|"&lt;BR /&gt;
fields = "name","age","sex","location"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83594#M17385</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2020-09-28T12:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: importing all the files available in a directory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83595#M17386</link>
      <description>&lt;P&gt;Please start a new question in the future. I assume you are getting multiple files indexed correctly?  &lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[USB]
SHOULD_LINEMERGE = false
KV_MODE = none
REPORT-my_fields = my_fields
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[my_fields]
DELIMS="|"
FIELDS = "name", "age", "sex", "location"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here's a previous splunk answers on this:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/3000/using-delims-to-extract-fix-data"&gt;http://splunk-base.splunk.com/answers/3000/using-delims-to-extract-fix-data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 19:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/importing-all-the-files-available-in-a-directory/m-p/83595#M17386</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-09T19:15:44Z</dc:date>
    </item>
  </channel>
</rss>

