- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to add an old ticketing system data to splunk?
splunk_user4
Explorer
11-20-2020
11:14 AM
I had the idea to upload our old ticketing systems data into splunk and create dashboards to search through the information instead of grep commands, I have a few csv files (9 to be exact) and was wondering the best way to move forward.
Questions to get me started:
Should I append them for one big CSV file?
Should I index the CSV files?
should I use a .zip file with all the CSVs inside?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
11-20-2020
02:39 PM
Hi
Without knowing your exact data, I will indexing those one by one with own sourcetype (if the content of file differs). All to one index.
Based on you exact data those other options could also be a good choices.
r. Ismo
Without knowing your exact data, I will indexing those one by one with own sourcetype (if the content of file differs). All to one index.
Based on you exact data those other options could also be a good choices.
r. Ismo
