<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with Ingesting Static File in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447114#M77776</link>
    <description>&lt;P&gt;What is the exact procedure you are using to ingest the CSV?&lt;/P&gt;</description>
    <pubDate>Sat, 16 Mar 2019 12:35:26 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-03-16T12:35:26Z</dc:date>
    <item>
      <title>Issues with Ingesting Static File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447113#M77775</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I've come across an odd problem, and I'm not sure where to start in troubleshooting.&lt;/P&gt;

&lt;P&gt;Once a week, on a Sunday, we ingest a csv file that contains all of our assets (splunk_devices.csv).  Recently, we have noticed that there are assets in the asset list that are not present in our asset index.&lt;/P&gt;

&lt;P&gt;Last week, for example, our static file contained 28k assets and the data ingested by Splunk only had 24k.  I reviewed the list myself and can confirm that the assets were missing from Splunk.  I ingested the file into my personal development environment with dev license and had no issues at all - All 28k assets were present and accounted for.&lt;/P&gt;

&lt;P&gt;I've found no error messages in Splunk, or any other indicators to start troubleshooting with.&lt;/P&gt;

&lt;P&gt;Does anyone have any ideas what we could check?  We're using Splunk Cloud, so have no access to indexers or search heads, but can access our forwarder infrastructure.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 05:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447113#M77775</guid>
      <dc:creator>MikeElliott</dc:creator>
      <dc:date>2019-03-16T05:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Ingesting Static File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447114#M77776</link>
      <description>&lt;P&gt;What is the exact procedure you are using to ingest the CSV?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 12:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447114#M77776</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-03-16T12:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Ingesting Static File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447115#M77777</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;

&lt;P&gt;We have a UF deployed on the asset that generates the list.  The list is updated on a daily basis, but only ingested by Splunk on a Sunday morning, around 2am.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 19:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447115#M77777</guid>
      <dc:creator>MikeElliott</dc:creator>
      <dc:date>2019-03-16T19:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Ingesting Static File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447116#M77778</link>
      <description>&lt;UL&gt;
&lt;LI&gt;Which exact command/procedure do you use to ingest the data?&lt;/LI&gt;
&lt;LI&gt;Are the missing devices at the beginning/end of your csv file in one big block?&lt;/LI&gt;
&lt;LI&gt;You could try to ingest the data into  a new (temporary) index on your prod-system if possible?&lt;/LI&gt;
&lt;LI&gt;Try the following: export your assets-index into a csv file; load this into a new index on your dev-system; ingest the "splunk_devices.csv" into this index also - does this work?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 16 Mar 2019 20:55:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447116#M77778</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2019-03-16T20:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Ingesting Static File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447117#M77779</link>
      <description>&lt;P&gt;What you describe does not sound like typical Splunk processing.  Universal forwarders ship data as it is received - they cannot update a list each day and send it to Splunk once a week.&lt;BR /&gt;
Please provide a &lt;EM&gt;detailed&lt;/EM&gt; explanation of how you get the asset list into Splunk.  Without that, we can only speculate about the problem.  Include the UF's inputs.conf settings for the CSV and the indexer's props.conf settings for the CSV's sourcetype.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2019 21:39:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issues-with-Ingesting-Static-File/m-p/447117#M77779</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-03-16T21:39:15Z</dc:date>
    </item>
  </channel>
</rss>

