Getting Data In

How to ingest only a specific file type within a tar.gz?

thisissplunk
Builder

I've got a ton of tar.gz's to ingest. Each one has three files in it, with one "results.txt" file that actually needs to be ingested. Can I/How do I tell Splunk to read those archives but only ingest the "results.txt" csv file within it?

I have a feeling I'll need to decompress everything and add the parent file name or something onto reach "results.txt" but I'm trying really hard to avoid that.

I understand inputs.conf, but I'm pretty sure I can only point Splunk to ingest the tar.gz files, not the files within the archives.

0 Karma

bcyates
Communicator

You can set a whitelist in your input stanza to only include files that read "results.txt" in the file name but if it's just one csv that you're interested in, it may be easier to untar and just upload the csv as a lookup table

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...