Getting Data In

Data collection not working- What should I check for collection of csv file data?

hhhwang
Explorer

Intermittent text file data collection is not possible.

Initially, it is a collection of csv file data.

After that, if you change only a few characters in the csv, you cannot collect them intermittently.

Which part should I check?

 

- setting

[monitor://D:\Space\Config*File\Devicenet_Config.csv]
disabled = 0
host = HOST_NAME
index = FDC_MainUtility
sourcetype = FDCField
crcSalt = <SOURCE>

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

What you describe sounds normal.  Splunk will not necessarily notice arbitrary character changes in a file.  If it does notice then it will re-index the entire file - possibly resulting in duplicate data.  Splunk expects new data to be written to the end of the file.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

What you describe sounds normal.  Splunk will not necessarily notice arbitrary character changes in a file.  If it does notice then it will re-index the entire file - possibly resulting in duplicate data.  Splunk expects new data to be written to the end of the file.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...