<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able to read CSV from Universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481703#M82559</link>
    <description>&lt;P&gt;Those are informational messages, I don't see an error. Also, don't set a &lt;CODE&gt;crcSalt&lt;/CODE&gt; if you don't need any.&lt;BR /&gt;
The file is not getting ingested? Any WARN or ERROR messages from TailingProcessor in your log?&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 09:51:33 GMT</pubDate>
    <dc:creator>skalliger</dc:creator>
    <dc:date>2020-01-10T09:51:33Z</dc:date>
    <item>
      <title>Not able to read CSV from Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481702#M82558</link>
      <description>&lt;P&gt;I am trying to read csv from one of my universal forwareder, below is my inputs file&lt;/P&gt;

&lt;P&gt;[monitor://D:\DUMP\Updated_Dump*.CSV]&lt;BR /&gt;
sourcetype=csv&lt;BR /&gt;
disabled=false&lt;BR /&gt;
index=xyz&lt;BR /&gt;
crcSalt=&lt;/P&gt;

&lt;P&gt;After checking splunkd log getting below events&lt;BR /&gt;
INFO  TailingProcessor - Adding watch on path: D:\DUMP&lt;BR /&gt;
INFO  TailingProcessor - Parsing configuration stanza: monitor://D:\DUMP\Updated_Dump*.CSV&lt;/P&gt;

&lt;P&gt;Please let me know how this can be resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 09:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481702#M82558</guid>
      <dc:creator>shugup2923</dc:creator>
      <dc:date>2020-01-10T09:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to read CSV from Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481703#M82559</link>
      <description>&lt;P&gt;Those are informational messages, I don't see an error. Also, don't set a &lt;CODE&gt;crcSalt&lt;/CODE&gt; if you don't need any.&lt;BR /&gt;
The file is not getting ingested? Any WARN or ERROR messages from TailingProcessor in your log?&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 09:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481703#M82559</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2020-01-10T09:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to read CSV from Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481704#M82560</link>
      <description>&lt;P&gt;crcSalt= is there, pasting error .&lt;BR /&gt;
 file is not getting ingested, can't see my data in search head, anyway to troubleshoot ?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481704#M82560</guid>
      <dc:creator>shugup2923</dc:creator>
      <dc:date>2020-01-10T10:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to read CSV from Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481705#M82561</link>
      <description>&lt;P&gt;as per logs, it seems it is reading the log file.&lt;BR /&gt;
what's the search you using to search the data? Have a search across all your splunk for some keyword from CSV. It might have come up as another sourcetype or different index&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* sourcetype=* &amp;lt;somekeyword_from_csv_file&amp;gt; earliest=-1000d latest=+100d | stats count by sourcetype,index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;run btool on sourcetype csv for props.conf &amp;amp; transforms.conf to check if it is getting overridden somewhere.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481705#M82561</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2020-01-10T10:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to read CSV from Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481706#M82562</link>
      <description>&lt;P&gt;I am using basic search - index=xyz sourcetype=csv &lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 07:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-read-CSV-from-Universal-forwarder/m-p/481706#M82562</guid>
      <dc:creator>shugup2923</dc:creator>
      <dc:date>2020-01-13T07:47:35Z</dc:date>
    </item>
  </channel>
</rss>

