<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I read a tgz file into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224476#M43946</link>
    <description>&lt;P&gt;I'm having issues with the link your provided.&lt;/P&gt;</description>
    <pubDate>Sun, 14 Aug 2016 20:56:01 GMT</pubDate>
    <dc:creator>sdse78</dc:creator>
    <dc:date>2016-08-14T20:56:01Z</dc:date>
    <item>
      <title>How can I read a tgz file into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224474#M43944</link>
      <description>&lt;P&gt;According to a book (&lt;STRONG&gt;Splunk Essentials By: Betsy Page Sigman&lt;/STRONG&gt;) I recently read on Splunk, Splunk can read in data from basically all types of files containing clear data, or as they put it, any data. Splunk can also decompress the following types of files: &lt;EM&gt;tar, gz, bz2, tar.gz, tgz, tbz, tbz2, zip, and z&lt;/EM&gt; along with many other formats. If this is true, how does it decompress the data? Specifically, if I am using "Add Data" within the manager can it first decompress a tgz file and then input it or do I need to decompress it first?&lt;/P&gt;

&lt;P&gt;I have a tgz file I am trying to input that is 1.08GB in size. However, every time I browse to it and try to input the file I get a message that the file is over 500MB and Splunk will not accept it.&lt;/P&gt;

&lt;P&gt;Can someone here help me solve this problem?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2016 17:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224474#M43944</guid>
      <dc:creator>sdse78</dc:creator>
      <dc:date>2016-08-13T17:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I read a tgz file into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224475#M43945</link>
      <description>&lt;P&gt;Splunk has the built in capability to un-zip/tar/z files. However, the GUI is limited, as it says, to files that are 500mb. That means, you cannot upload a file that is over 500mg. &lt;/P&gt;

&lt;P&gt;You  will need to use oneshot, or setup a monitor on the file to ingest it into Splunk. You should read here : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Data/MonitorfilesanddirectoriesusingtheCLI"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Data/MonitorfilesanddirectoriesusingtheCLI&lt;/A&gt; . That describes everything you need to do to get your large tgz file ingested into Splunk.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Aug 2016 03:18:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224475#M43945</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2016-08-14T03:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can I read a tgz file into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224476#M43946</link>
      <description>&lt;P&gt;I'm having issues with the link your provided.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Aug 2016 20:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224476#M43946</guid>
      <dc:creator>sdse78</dc:creator>
      <dc:date>2016-08-14T20:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: How can I read a tgz file into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224477#M43947</link>
      <description>&lt;P&gt;I fixed the link in esix's answer.  The editor decided the period at the end of the sentence was part of the URL, so I added a space and now it works.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 00:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224477#M43947</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-08-15T00:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: How can I read a tgz file into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224478#M43948</link>
      <description>&lt;P&gt;Thank you rich7177. I greatly appreciate it.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 00:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-read-a-tgz-file-into-Splunk/m-p/224478#M43948</guid>
      <dc:creator>sdse78</dc:creator>
      <dc:date>2016-08-15T00:12:55Z</dc:date>
    </item>
  </channel>
</rss>

