Getting Data In

How to do a one time file upload through conf files?

deva1995
Explorer

I want to upload a log file from my computer, through conf files. There will be no monitoring just uploading file only for once. So, which conf file i need to add and what stanzas i need to put in those files?

0 Karma

somesoni2
Revered Legend

What's your use-case? Any specific reason for just one time upload?

0 Karma

deva1995
Explorer

I want to mask some information in the data I have in my pc. So, i wanted to edit transforms.conf, and upload the data through conf files so that data masking can take place at the indexing time.

0 Karma

adonio
Ultra Champion

you can create the props and transforms on your indexer and when using oneshot, specify the sourcetype.
that will apply your rules of masking to your data

adonio
Ultra Champion

hello there, for one time upload,
run the command splunk add oneshot
see full description here:
https://docs.splunk.com/Documentation/Splunk/7.0.3/Data/MonitorfilesanddirectoriesusingtheCLI
if the data is smaller than 500MB, you can drag and drop in the "add data" page

hope it helps

deva1995
Explorer

this is uploading through CLI, i want to upload the data through conf files.

0 Karma

adonio
Ultra Champion

you can create the props and transforms on your indexer and when using oneshot, specify the sourcetype.
that will apply your rules of masking to your data
you can not do one shot through conf files. you can setup the monitor stanza one time and than disable / comment it out

0 Karma

p_gurav
Champion

Is it distributed environment or single instance?

0 Karma

deva1995
Explorer

single instance.

0 Karma

p_gurav
Champion

Then you should try one shot command suggested by @adonio.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...