<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder and CSV (from Remote System) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176713#M35451</link>
    <description>&lt;P&gt;The inputs.conf is probably not necessary, because you already have one on the forwarder.  What you will need to do is add the new sourcetype to the input stanza on the forwarder like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[monitor://D:\web\System_Availablity_Analytics\*.csv]&lt;BR /&gt;
sourcetype = csv-2&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2014 20:58:15 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2014-03-06T20:58:15Z</dc:date>
    <item>
      <title>Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176700#M35438</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a Universal Forwarder whose source file is reading all files in a specific directory , the dir has many files including HTM and CSV files, forwarder is reading all HTML files but not CSV by default. SO indexer is not seeing that data which in CSV file....what am i missing here.&lt;/P&gt;

&lt;P&gt;From remote system&lt;BR /&gt;
Here is my input.conf &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = ABCD

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[monitor://D:\web\System_Availablity_Analytics\*.csv]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Mar 2014 19:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176700#M35438</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-06T19:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176701#M35439</link>
      <description>&lt;P&gt;Are you seeing any errors in the splunkd log?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 19:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176701#M35439</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T19:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176702#M35440</link>
      <description>&lt;P&gt;Yes i see them &lt;BR /&gt;
03-06-2014 13:14:45.760 -0600 ERROR TailingProcessor - Ignoring path="D:\web\System_Availablity_Analytic\Report.csv" due to: Cannot checksum file due to unknown charset="AUTO".f&lt;BR /&gt;
03-06-2014 13:14:50.635 -0600 ERROR ExecProcessor - message from ""C:\Program Files\SplunkForwarder\bin\splunk-MonitorNoHandle.exe"" wmain: Operating system major version 5, detected -- A minimum of 6 (VISTA/Server 2008) is required. Exitting.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176702#M35440</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2020-09-28T16:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176703#M35441</link>
      <description>&lt;P&gt;03-06-2014 13:14:55.651 -0600 ERROR ExecProcessor - message from ""C:\Program Files\SplunkForwarder\bin\splunk-netmon.exe"" splunk-netmon - Splunk network monitor is not available on this version of Windows.&lt;BR /&gt;
03-06-2014 13:15:00.651 -0600 INFO  ExecProcessor - message from ""C:\Program Files\SplunkForwarder\bin\splunk-regmon.exe""  splunk-regmon - SysmonMigrator::read - 'sysmon.conf' was not found, no migration is required.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 19:28:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176703#M35441</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-06T19:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176704#M35442</link>
      <description>&lt;P&gt;Only the first one relates to your csv problem.&lt;BR /&gt;&lt;BR /&gt;
Does the file use a character set other than utf-8 or ascii?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 19:35:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176704#M35442</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T19:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176705#M35443</link>
      <description>&lt;P&gt;no it should be ASCII....&lt;/P&gt;

&lt;P&gt;Here is CSV file&lt;/P&gt;

&lt;P&gt;"","Availability"&lt;BR /&gt;
"","%"&lt;BR /&gt;
"","All"&lt;BR /&gt;
"",""&lt;BR /&gt;
"Element",""&lt;BR /&gt;
"ABCD",100.00000000&lt;/P&gt;

&lt;P&gt;"Auto Range:  Previous Hour","Subject:  REPORT","Created: 03/06/2014 12:55:03 PM"&lt;BR /&gt;
"From:  03/06/2014 11:55 AM","","Time Zone: (GMT-06:00) Central Time"&lt;BR /&gt;
"To:  03/06/2014 12:55 PM"&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 19:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176705#M35443</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-06T19:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176706#M35444</link>
      <description>&lt;P&gt;Is that the whole thing or one event?&lt;BR /&gt;
I would copy one of the files to the indexer c:temp directory, and use the monitor files and directories GUI to create the inputs.conf and props.conf configs, and then transfer those configs to the forwarder.&lt;BR /&gt;
If you do this, when you transfer the configs you will have to correct the monitor path when you move the configs to the forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 19:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176706#M35444</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T19:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176707#M35445</link>
      <description>&lt;P&gt;no its whole file...&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176707#M35445</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-06T20:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176708#M35446</link>
      <description>&lt;P&gt;so if i create this through indexer ....next time this file is overwritten will it work?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176708#M35446</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-06T20:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176709#M35447</link>
      <description>&lt;P&gt;The source will be different, so yes.  Once you are done creating the configs and move them to the forwarder, then you can delete the input from the indexer.  Don't forget to use a test index, and change the index in inputs.conf to 'main' when you move the configs to the forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176709#M35447</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T20:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176710#M35448</link>
      <description>&lt;P&gt;ok confused a little bit...&lt;BR /&gt;
I put this in indexer and used GUI to map CSV file -  i see it indexed the CSV file locally and it shows content on the Summary Tab&lt;/P&gt;

&lt;P&gt;Now when i go to find indexer.conf and props.conf - i see many of them on system but not sure where it made change...which file will it write to and what i need to change before i move to unversal forwarder. Thanks for your help on this.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:32:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176710#M35448</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-06T20:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176711#M35449</link>
      <description>&lt;P&gt;On the indexer, check &lt;CODE&gt;etc/apps/?/local/inputs.conf&lt;/CODE&gt; for the input.  The app might be will be what ever app you were in before you went to the manager.&lt;BR /&gt;
The props.conf will be in the &lt;CODE&gt;etc/apps/learned/local/props.conf&lt;/CODE&gt;&lt;BR /&gt;
You will only need the stanzas for the input you created in inputs.conf, and the sourcetype that was created in props.conf.  They should both be at the bottom.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176711#M35449</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T20:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176712#M35450</link>
      <description>&lt;P&gt;i dont see anything in input.conf which has changed today (search app is default), props.conf has this entry&lt;BR /&gt;
[csv-2]&lt;BR /&gt;
KV_MODE = none&lt;BR /&gt;
REPORT-AutoHeader = AutoHeader-1&lt;BR /&gt;
SHOULD_LINEMERGE = False&lt;BR /&gt;
pulldown_type = true&lt;/P&gt;

&lt;P&gt;So should go to same place in Universal Forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176712#M35450</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2020-09-28T16:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176713#M35451</link>
      <description>&lt;P&gt;The inputs.conf is probably not necessary, because you already have one on the forwarder.  What you will need to do is add the new sourcetype to the input stanza on the forwarder like this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[monitor://D:\web\System_Availablity_Analytics\*.csv]&lt;BR /&gt;
sourcetype = csv-2&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:58:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176713#M35451</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T20:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176714#M35452</link>
      <description>&lt;P&gt;and i see the data , here is what i did &lt;BR /&gt;
Added stanza to etc/apps/learned/local/props.conf and modified input.conf to listen &lt;BR /&gt;
[monitor://D:\web\System_Availablity_Analytics*.csv] sourcetype = csv-2&lt;/P&gt;

&lt;P&gt;Thanks for all help on this, lastly - i see the file being read by indexer as breaking events not the way i like - in order for me to make it learn how it reads:&lt;/P&gt;

&lt;P&gt;In past i was building props.conf of a particular application to write logic to split where i want to, is it best to put the Global Props.conf in Search App and any new App i build will leverage that?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:03:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176714#M35452</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2020-09-28T16:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176715#M35453</link>
      <description>&lt;P&gt;Good news.  If you can provide specifics then perhaps we can help.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 21:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176715#M35453</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-06T21:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176716#M35454</link>
      <description>&lt;P&gt;The best place to put global props.conf stuff is on the indexer in &lt;CODE&gt;etc/system/local&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2014 15:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176716#M35454</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-03-07T15:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and CSV (from Remote System)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176717#M35455</link>
      <description>&lt;P&gt;Also where is best place to put the same props.conf in Universal Forwarder&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 03:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-CSV-from-Remote-System/m-p/176717#M35455</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-03-12T03:03:07Z</dc:date>
    </item>
  </channel>
</rss>

