Getting Data In

How to ingest more than 1000 events using the monitor setting from the WUI

raby1996
Path Finder

Hello all,
My question is that I have a cvs file that is being updated every hour or so lets say its called test.csv , and I would like to have spunk monitor the file so it updates automatically. Ive been trying the monitor option under add new data inputs, and everything seems to be working except for the fact that my events are being cut off at 1000, there are over 2000 lines ( each one an event) and I would like to ingest them all, is there any way I can do this ? My current setting are as listed below. Thank you in advance.
alt text

Tags (3)
0 Karma
1 Solution

somesoni2
Revered Legend

First, the attributes are case sensitive, so check the case for MAX_EVENTS property.
Second, the preview tool has limitation on number events shown in preview but once the file monitoring is setup, all event will get ingested. So, do you see truncation after the monitoring is setup?

View solution in original post

somesoni2
Revered Legend

First, the attributes are case sensitive, so check the case for MAX_EVENTS property.
Second, the preview tool has limitation on number events shown in preview but once the file monitoring is setup, all event will get ingested. So, do you see truncation after the monitoring is setup?

Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...