Getting Data In

How to ingest more than 1000 events using the monitor setting from the WUI

raby1996
Path Finder

Hello all,
My question is that I have a cvs file that is being updated every hour or so lets say its called test.csv , and I would like to have spunk monitor the file so it updates automatically. Ive been trying the monitor option under add new data inputs, and everything seems to be working except for the fact that my events are being cut off at 1000, there are over 2000 lines ( each one an event) and I would like to ingest them all, is there any way I can do this ? My current setting are as listed below. Thank you in advance.
alt text

Tags (3)
0 Karma
1 Solution

somesoni2
Revered Legend

First, the attributes are case sensitive, so check the case for MAX_EVENTS property.
Second, the preview tool has limitation on number events shown in preview but once the file monitoring is setup, all event will get ingested. So, do you see truncation after the monitoring is setup?

View solution in original post

somesoni2
Revered Legend

First, the attributes are case sensitive, so check the case for MAX_EVENTS property.
Second, the preview tool has limitation on number events shown in preview but once the file monitoring is setup, all event will get ingested. So, do you see truncation after the monitoring is setup?

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...