Getting Data In

Can't index a .csv file?!?

Jochen_1987
Explorer

Hey,
I tried to index a .csv file several times and I can see the file in
"Manager » Data inputs » Files & directories" but I can't find it?!?!
I tried a different file and directory and there was the same result...
I can also see all indexes due to the settings of "Access controls » Roles".
To make a long story short I have no idea why i can't find the files that are indexed....

Tags (2)
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi Jochen

is your input index into another then the default index?

if so, do you search the correct index?

what does splunkd.log report?

have you searched index=_internal for the file in question?

cheers,

MuS

View solution in original post

proletariat99
Communicator

same problem here. I've put it in default, main, created my own new index, given it default sourcetypes and custom sourcetypes and it just doesn't appear anywhere.

Never indexed, never uploaded, as far as I can tell. What gives?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi Jochen

is your input index into another then the default index?

if so, do you search the correct index?

what does splunkd.log report?

have you searched index=_internal for the file in question?

cheers,

MuS

Jochen_1987
Explorer

ok, now I now why it doesn't work, but how do i get the data back in splunk:-)?

0 Karma

Ayn
Legend

That could very well be the problem. Splunk keeps track of how far into the file it has read. If you delete the file and reupload it, it will not be reindexed. Some more information is available here: http://docs.splunk.com/Documentation/Splunk/latest/Data/Howlogfilerotationishandled

0 Karma

MuS
SplunkTrust
SplunkTrust

okay, splunk will not index this file again in this case.
just make sure there is no permission problem and the path is accessible for splunk, then it should be fine. do you use any regex for this input and props/transforms as well?
could you post the stanza from inputs.conf?

0 Karma

Jochen_1987
Explorer

no result... the thing is I already indexed the file a few days ago but then deleted it... could that be the problem? and if i want to upload a file that's fine, i just got problems if i want to monitor a file/directory...

0 Karma

ryantzj
Explorer

Having a very similar problem on my side, May i know what you did to resolve this.

0 Karma

MuS
SplunkTrust
SplunkTrust
0 Karma

MuS
SplunkTrust
SplunkTrust

it could also be a permission problem, meaning the user splunk is running is not allowed to read the file.
try searching for the file name in index=_internal instead of path name.

0 Karma

Jochen_1987
Explorer

Hi,
Input index is default index... Splunkd.log reports "TailingProcessor - Parsing configuration stanza: monitor:C:..." and I searched index=_internal and then the path of the file but there were no results..

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...