Deployment Architecture

Monitoring csv file using Universal forwarder missing some data into index

c_krishna_gutur
Explorer

I have Task Scheduler which runs for every 6 hours and generates .csv file into a folder, I am monitoring this file using universal forwarder, for the last 15 to 20 days it works as expected, now the indexing is not happening completely i.e it is not taking all the records into index Ex: My .csv file contains 800 records but it is indexing around 225 records, why is this behaviour ? Any thoughts ?

Tags (1)
0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi Krishna,

Please try the following:

  1. Stop your indexer and forwarder.
  2. On the indexer, reset the csv input checkpoint, use the btprobe command: splunk cmd btprobe –d SPLUNK_HOME/var/lib/splunk/ fishbucket/splunk_private_db --file --reset
  3. Start your indexer and forwarder.

Hope it helps. Thanks!
Hunter

0 Karma
Get Updates on the Splunk Community!

Best Strategies to Optimize Observability Costs

 Join us on Tuesday, May 6, 2025, at 11 AM PDT / 2 PM EDT for an insightful session on optimizing ...

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...