Getting Data In

How to make a dashboard from txt health sheets file

aamirulh
New Member

aamirulh_0-1647824237356.png

Hi, Im really new to the splunk, having problem where i need to make a dashboard from txt health sheets file, could anyone help me? It read the data like that

Labels (1)
0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @aamirulh,

I also faced a similar issue earlier while monitoring the windows event logs. If the data you are trying to read is windows event logs, try assigning winevt-preprocess sourcetype to the data in the monitor stanza and have the file ingested. 

Please find the reference stanza below:

[monitor://C:\Program Files\SplunkUniversalForwarder\tmp\file.evtx]                                                                               
index=<<index_name>>                                                                                                                                                   
disabled=0                                                                                                                                                        
renderXml=false                                                                                                                                                   
sourcetype=preprocess-winevt

PS. This will not work with the Add Data GUI operation. 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...