Getting Data In

Index time csv monitor

sean193
Explorer

Hey All,

Having issues getting data in.  With the inputs monitor stanza only data comes thru but when I add the props to do indexed time field extractions data stops coming all together.  No errors are seen in _internal, anyone got some ideas? 

Inputs.conf
[monitor://C:\file\data\]
whitelist = file1.csv$
index = file1
sourcetype = file1
disabled = false

Props.conf
[file1]
INDEXED_EXTRACTIONS = CSV
FIELD_DELIMETER=,
FIELD_QUOTE="
HEADER_FIELD_DELIMETER=,

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...