I have installed Splunk Enterprise in an AWS instance.
i have installed the Splunk Hadoop Connect app also and it's working well.
i have exported the raw file from Splunk to Hadoop.
But in Hadoop, it's showing a .cursor file. Please tell me how to analyze that cursor file in Hadoop.
Please also let me know the usage of hunk and its download path with step by step set up.
Yes, the cursor file is expected, but you should also be able to see the .gz file after the job is done.
Here is the link to the docs that explain the cursor and hdfs files: