Hi, Im really new to the splunk, having problem where i need to make a dashboard from txt health sheets file, could anyone help me? It read the data like that
Hey @aamirulh,
I also faced a similar issue earlier while monitoring the windows event logs. If the data you are trying to read is windows event logs, try assigning winevt-preprocess sourcetype to the data in the monitor stanza and have the file ingested.
Please find the reference stanza below:
[monitor://C:\Program Files\SplunkUniversalForwarder\tmp\file.evtx]
index=<<index_name>>
disabled=0
renderXml=false
sourcetype=preprocess-winevt
PS. This will not work with the Add Data GUI operation.