<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic &amp;quot;splunk add oneshot&amp;quot; not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520219#M87936</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Trying to test a sourcetype using "oneshot".&amp;nbsp; Although we were able to add raw data using "oneshot" the first time, we are not seeing any subsequent updates.&amp;nbsp; The command we are using is ...&lt;/P&gt;&lt;P&gt;splunk add oneshot /tmp/&amp;lt;filename&amp;gt;.txt -index &amp;lt;indexname&amp;gt; -sourcetype &amp;lt;sourcetypename&amp;gt;&lt;/P&gt;&lt;P&gt;What are the best approaches to troubleshoot "oneshot"?&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Max&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Sep 2020 22:00:46 GMT</pubDate>
    <dc:creator>vpsmax</dc:creator>
    <dc:date>2020-09-17T22:00:46Z</dc:date>
    <item>
      <title>"splunk add oneshot" not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520219#M87936</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Trying to test a sourcetype using "oneshot".&amp;nbsp; Although we were able to add raw data using "oneshot" the first time, we are not seeing any subsequent updates.&amp;nbsp; The command we are using is ...&lt;/P&gt;&lt;P&gt;splunk add oneshot /tmp/&amp;lt;filename&amp;gt;.txt -index &amp;lt;indexname&amp;gt; -sourcetype &amp;lt;sourcetypename&amp;gt;&lt;/P&gt;&lt;P&gt;What are the best approaches to troubleshoot "oneshot"?&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Max&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 22:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520219#M87936</guid>
      <dc:creator>vpsmax</dc:creator>
      <dc:date>2020-09-17T22:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: "splunk add oneshot" not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520223#M87948</link>
      <description>&lt;P&gt;Hi Max,&lt;BR /&gt;&lt;BR /&gt;Please try:&lt;BR /&gt;&lt;BR /&gt;splunk add oneshot -source /tmp/&amp;lt;filename&amp;gt;.txt -index &amp;lt;indexname&amp;gt; -sourcetype &amp;lt;sourcetypename&amp;gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-bd-&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 23:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520223#M87948</guid>
      <dc:creator>bdiego_splunk</dc:creator>
      <dc:date>2020-09-17T23:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: "splunk add oneshot" not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520230#M87949</link>
      <description>&lt;P&gt;Hi Max, use this command to check if the file status of the file has been reset&lt;/P&gt;&lt;P&gt;splunk cmd btprobe -d $SPLUNK_DB/fishbucket/splunk_private_db --file &amp;lt;file&amp;gt; --reset&lt;/P&gt;&lt;P&gt;The response from this command is an indicator that the status for the file has been reset. Again, a restart of the forwarder is required for Splunk to then ingest that file anew.&lt;/P&gt;&lt;P&gt;if this assist you, please upvote.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 00:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/520230#M87949</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2020-09-18T00:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: "splunk add oneshot" not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/698453#M115794</link>
      <description>&lt;P&gt;We need to remember that Universal Forward does not do index-time parsing, on the other hand a Splunk Enterprise server such as a Heavy Forwarder, Search Head, Deployment server, depoyer, etc does the index-time parsing.&amp;nbsp; Indexers&amp;nbsp; expect that the data that come via another Splunk Enterprise server have the data cooked.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 16:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-splunk-add-oneshot-quot-not-working/m-p/698453#M115794</guid>
      <dc:creator>anwarmian</dc:creator>
      <dc:date>2024-09-07T16:35:51Z</dc:date>
    </item>
  </channel>
</rss>

