Archive
Highlighted

Monitoring csv file using Universal forwarder missing some data into index

I have Task Scheduler which runs for every 6 hours and generates .csv file into a folder, I am monitoring this file using universal forwarder, for the last 15 to 20 days it works as expected, now the indexing is not happening completely i.e it is not taking all the records into index Ex: My .csv file contains 800 records but it is indexing around 225 records, why is this behaviour ? Any thoughts ?

Tags (1)
0 Karma
Highlighted

Re: Monitoring csv file using Universal forwarder missing some data into index

Splunk Employee
Splunk Employee

Hi Krishna,

Please try the following:

  1. Stop your indexer and forwarder.
  2. On the indexer, reset the csv input checkpoint, use the btprobe command: splunk cmd btprobe –d SPLUNKHOME/var/lib/splunk/ fishbucket/splunkprivate_db --file --reset
  3. Start your indexer and forwarder.

Hope it helps. Thanks!
Hunter

0 Karma