<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I use/activate the short term bulk loading using the Splunk free version? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401544#M95122</link>
    <description>&lt;P&gt;Hi all, Currently I am using the Splunk Free version. However, i would like to import the splunk bots dataset into the splunk server to . They are 6GB large. &lt;/P&gt;

&lt;P&gt;According to splunk free documentation on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/MoreaboutSplunkFree"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/MoreaboutSplunkFree&lt;/A&gt;,&lt;/P&gt;

&lt;P&gt;"Is Splunk Free for you?&lt;BR /&gt;
Splunk Free is designed for personal, ad hoc search and visualization of IT data. You can use Splunk Free for ongoing indexing of small volumes (&amp;lt;500 MB/day) of data. Additionally, you can use it for short-term bulk-loading and analysis of larger data sets--Splunk Free lets you bulk-load much larger data sets up to 3 times within a 30 day period. This can be useful for forensic review of large data sets."&lt;/P&gt;

&lt;P&gt;How do I use/activate the short term bulk loading? I tried to import the dataset via installing a app, but received the error message of maximum size is 500mb. &lt;/P&gt;</description>
    <pubDate>Sun, 02 Jun 2019 03:19:06 GMT</pubDate>
    <dc:creator>yihan</dc:creator>
    <dc:date>2019-06-02T03:19:06Z</dc:date>
    <item>
      <title>How do I use/activate the short term bulk loading using the Splunk free version?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401544#M95122</link>
      <description>&lt;P&gt;Hi all, Currently I am using the Splunk Free version. However, i would like to import the splunk bots dataset into the splunk server to . They are 6GB large. &lt;/P&gt;

&lt;P&gt;According to splunk free documentation on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/MoreaboutSplunkFree"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/MoreaboutSplunkFree&lt;/A&gt;,&lt;/P&gt;

&lt;P&gt;"Is Splunk Free for you?&lt;BR /&gt;
Splunk Free is designed for personal, ad hoc search and visualization of IT data. You can use Splunk Free for ongoing indexing of small volumes (&amp;lt;500 MB/day) of data. Additionally, you can use it for short-term bulk-loading and analysis of larger data sets--Splunk Free lets you bulk-load much larger data sets up to 3 times within a 30 day period. This can be useful for forensic review of large data sets."&lt;/P&gt;

&lt;P&gt;How do I use/activate the short term bulk loading? I tried to import the dataset via installing a app, but received the error message of maximum size is 500mb. &lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2019 03:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401544#M95122</guid>
      <dc:creator>yihan</dc:creator>
      <dc:date>2019-06-02T03:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I use/activate the short term bulk loading using the Splunk free version?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401545#M95123</link>
      <description>&lt;P&gt;Hi @yihan, what do you mean tried importing the dataset via installing an app ? Did you setup a monitor on the required files via inputs.conf or GUI ?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2019 12:18:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401545#M95123</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-02T12:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do I use/activate the short term bulk loading using the Splunk free version?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401546#M95124</link>
      <description>&lt;P&gt;Hi @yihan &lt;/P&gt;

&lt;P&gt;How did you input the log file?  If you are uploading with Splunk WebUI, it is failing due to HTTP file transfer size limitation.  It is not a license limitation.&lt;BR /&gt;&lt;BR /&gt;
When importing logs larger than 500MB, split the file so that one file is less than 500MB.  Then try uploading from WebUI.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2019 12:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401546#M95124</guid>
      <dc:creator>soskaykakehi</dc:creator>
      <dc:date>2019-06-02T12:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do I use/activate the short term bulk loading using the Splunk free version?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401547#M95125</link>
      <description>&lt;P&gt;Other option is using input monitor or oneshot command.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2019 12:32:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401547#M95125</guid>
      <dc:creator>soskaykakehi</dc:creator>
      <dc:date>2019-06-02T12:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I use/activate the short term bulk loading using the Splunk free version?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401548#M95126</link>
      <description>&lt;P&gt;The dataset given from splunk for Bots SOC is given as an app to import: &lt;A href="https://github.com/splunk/botsv1"&gt;https://github.com/splunk/botsv1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2019 15:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-use-activate-the-short-term-bulk-loading-using-the/m-p/401548#M95126</guid>
      <dc:creator>yihan</dc:creator>
      <dc:date>2019-06-02T15:20:15Z</dc:date>
    </item>
  </channel>
</rss>

