Deployment Architecture

How to ingest csv file into Heavy forwarder instance and forward data to a peer index

Sabareesh
Observer

I need to get the csv file into HF and forward it to an indexer

How do i add csv file to HF...Do i need to create stanza in inputs.conf to monitor the file.If pls let me know the stanza.

Labels (2)
0 Karma

saravanan90
Contributor

The stanza will monitor the temp.csv file in HF & forward it to indexer.

The temp.csv can be placed manually or pushed through any script to that path.

0 Karma

saravanan90
Contributor

Below may help. 

For Linux :

[monitor:///opt/splunk/var/log/splunk/temp.csv]
index = main
sourcetype = csv
disabled = 0
crcSalt = <SOURCE>

 

For Windows

[monitor://C:\splunk\var\log\splunk\temp.csv]
index = main
sourcetype = csv
disabled = 0
crcSalt = <SOURCE>

0 Karma

Sabareesh
Observer

Thanks for the Stanza.

I want to know how to place a temp.csv file into that path?

0 Karma

KimiYan
New Member

Dear friend, have you solved your problem ? I have the same requirements as yours. Hope you can share your stanza.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...