Deployment Architecture

Monitoring csv file using Universal forwarder missing some data into index

c_krishna_gutur
Explorer

I have Task Scheduler which runs for every 6 hours and generates .csv file into a folder, I am monitoring this file using universal forwarder, for the last 15 to 20 days it works as expected, now the indexing is not happening completely i.e it is not taking all the records into index Ex: My .csv file contains 800 records but it is indexing around 225 records, why is this behaviour ? Any thoughts ?

Tags (1)
0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi Krishna,

Please try the following:

  1. Stop your indexer and forwarder.
  2. On the indexer, reset the csv input checkpoint, use the btprobe command: splunk cmd btprobe –d SPLUNK_HOME/var/lib/splunk/ fishbucket/splunk_private_db --file --reset
  3. Start your indexer and forwarder.

Hope it helps. Thanks!
Hunter

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...