Deployment Architecture

Monitoring csv file using Universal forwarder missing some data into index

c_krishna_gutur
Explorer

I have Task Scheduler which runs for every 6 hours and generates .csv file into a folder, I am monitoring this file using universal forwarder, for the last 15 to 20 days it works as expected, now the indexing is not happening completely i.e it is not taking all the records into index Ex: My .csv file contains 800 records but it is indexing around 225 records, why is this behaviour ? Any thoughts ?

Tags (1)
0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi Krishna,

Please try the following:

  1. Stop your indexer and forwarder.
  2. On the indexer, reset the csv input checkpoint, use the btprobe command: splunk cmd btprobe –d SPLUNK_HOME/var/lib/splunk/ fishbucket/splunk_private_db --file --reset
  3. Start your indexer and forwarder.

Hope it helps. Thanks!
Hunter

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...