Deployment Architecture

How to ingest csv file into Heavy forwarder instance and forward data to a peer index

Sabareesh
Observer

I need to get the csv file into HF and forward it to an indexer

How do i add csv file to HF...Do i need to create stanza in inputs.conf to monitor the file.If pls let me know the stanza.

Labels (2)
0 Karma

saravanan90
Contributor

The stanza will monitor the temp.csv file in HF & forward it to indexer.

The temp.csv can be placed manually or pushed through any script to that path.

0 Karma

saravanan90
Contributor

Below may help. 

For Linux :

[monitor:///opt/splunk/var/log/splunk/temp.csv]
index = main
sourcetype = csv
disabled = 0
crcSalt = <SOURCE>

 

For Windows

[monitor://C:\splunk\var\log\splunk\temp.csv]
index = main
sourcetype = csv
disabled = 0
crcSalt = <SOURCE>

0 Karma

Sabareesh
Observer

Thanks for the Stanza.

I want to know how to place a temp.csv file into that path?

0 Karma

KimiYan
New Member

Dear friend, have you solved your problem ? I have the same requirements as yours. Hope you can share your stanza.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...