Getting Data In

How to add an old ticketing system data to splunk?


I had the idea to upload our old ticketing systems data into splunk and create dashboards to search through the information instead of grep commands, I have a few csv files (9 to be exact) and was wondering the best way to move forward.  

Questions to get me started: 
Should I append them for one big CSV file?

Should I index the CSV files?

should I use a .zip file with all the CSVs inside?



Labels (4)
Tags (2)
0 Karma

Without knowing your exact data, I will indexing those one by one with own sourcetype (if the content of file differs). All to one index.
Based on you exact data those other options could also be a good choices.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: CFP Site: CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...