Getting Data In

How to make a dashboard from txt health sheets file

aamirulh
New Member

aamirulh_0-1647824237356.png

Hi, Im really new to the splunk, having problem where i need to make a dashboard from txt health sheets file, could anyone help me? It read the data like that

0 Karma

tshah-splunk
Splunk Employee
Splunk Employee

Hey @aamirulh,

I also faced a similar issue earlier while monitoring the windows event logs. If the data you are trying to read is windows event logs, try assigning winevt-preprocess sourcetype to the data in the monitor stanza and have the file ingested. 

Please find the reference stanza below:

[monitor://C:\Program Files\SplunkUniversalForwarder\tmp\file.evtx]                                                                               
index=<<index_name>>                                                                                                                                                   
disabled=0                                                                                                                                                        
renderXml=false                                                                                                                                                   
sourcetype=preprocess-winevt

PS. This will not work with the Add Data GUI operation. 

---
If you find the answer helpful, an upvote/karma is appreciated
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...