I'm trying to batch upload many files on my windows computer (some >150mb) using an inputs.conf file.
I have the inputs.conf file saved in C:\Program Files\Splunk\etc\apps\search\local
The contents of the file are
[batch://C:\Temp\Data\Sample\*]
index=test3
# host_segment=3
sourcetype=access_combined
recursive=true
move_policy = sinkhole
The data I want to upload is saved in C:\Temp\Data\Sample\
I have the index test3 created. When I log into Splunk the index is still empty.
Any help to fix this?
Hi there,
try to search all time
or use this quick search SPL | tstats count WHERE index=test3
to see if you get events. Also check index=_internal
for any warnings or errors related to c:\temp\data\sample
cheers, MuS