Getting Data In

Add CSV file as a source by a script

isedrof
Engager

Hey guys,
I'm back with an another question, the goal is to add data (CSV file ) as a source to splunk by a script. Without to proceed by adding it With Upload button.
So i really need, is to know the real format of files whene they're in Splunk. because last time a added a lookups files directly by going to the right path. the problem here is whene i add CSV file as a Source and i look in Splunk it doesn't keep the same format, i guess it's a deal with input.conf file.
Thanks again for your help.

0 Karma

woodcock
Esteemed Legend

By far, the easiest way to inject data by script is to use the oneshot method; search for "oneshot" and read about it here:

http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/MonitorfilesanddirectoriesusingtheCLI

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I've installed many CSV files in Splunk from the command line. The format is a simple text file using the line endings appropriate for the platform (Linux, in my case). I've never had to change inputs.conf for my CSVs. Make sure you're putting the files in the right location - $SPLUNK_HOME/etc/apps/myapp/lookups or $SPLUNK_HOME/etc/system/lookups.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isedrof
Engager

Here you're talking about lookups files ..but this not what i want to do ..what i want is to add them like a Source.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please explain what you mean by "like a Source". What exactly do you intend to do with the files?

---
If this reply helps you, Karma would be appreciated.
0 Karma

isedrof
Engager

In splunk you can manage files by upload them directly (the first page) or by uploading them like a lookups file.
if you upload them directly they're indexed like a source not like a lookup file.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

So you want to index your CSV. Perhaps this answer http://answers.splunk.com/answers/260391/how-to-add-data-to-splunk-with-custom-source-and-s.html will help.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...