Getting Data In

After upgrade to 7.3.1 file upload is stopping after 80 events

a238574
Path Finder

I have a file monitor running on my heavy forwarder and after my upgrade to 7.3.1 it is only loading the 1st 80 events.. there are over 600 events in the file and this worked fine prior to the upgrade. I am thinking there is an update to a config file somewhere that is limiting the upload.

Tags (1)
0 Karma

a238574
Path Finder

upgraded from 6.6

0 Karma

burwell
SplunkTrust
SplunkTrust

Hi. So fire example you only have 80 events from your _internal index?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...