I'm trying to batch upload many files on my windows computer (some >150mb) using an inputs.conf file.
I have the inputs.conf file saved in C:\Program Files\Splunk\etc\apps\search\local
The contents of the file are
move_policy = sinkhole
The data I want to upload is saved in C:\Temp\Data\Sample\
I have the index test3 created. When I log into Splunk the index is still empty.
Any help to fix this?
try to search all time or use this quick search SPL | tstats count WHERE index=test3 to see if you get events. Also check index=_internal for any warnings or errors related to c:\temp\data\sample
| tstats count WHERE index=test3