Getting Data In

How to bulk upload data using inputs.conf?

parwindertaank
Explorer

I'm trying to batch upload many files on my windows computer (some >150mb) using an inputs.conf file.

I have the inputs.conf file saved in C:\Program Files\Splunk\etc\apps\search\local
The contents of the file are

[batch://C:\Temp\Data\Sample\*]
index=test3
# host_segment=3
sourcetype=access_combined
recursive=true
move_policy = sinkhole

The data I want to upload is saved in C:\Temp\Data\Sample\

I have the index test3 created. When I log into Splunk the index is still empty.

Any help to fix this?

0 Karma

MuS
Legend

Hi there,

try to search all time or use this quick search SPL | tstats count WHERE index=test3 to see if you get events. Also check index=_internal for any warnings or errors related to c:\temp\data\sample

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...