Getting Data In

Index time csv monitor

sean193
Explorer

Hey All,

Having issues getting data in.  With the inputs monitor stanza only data comes thru but when I add the props to do indexed time field extractions data stops coming all together.  No errors are seen in _internal, anyone got some ideas? 

Inputs.conf
[monitor://C:\file\data\]
whitelist = file1.csv$
index = file1
sourcetype = file1
disabled = false

Props.conf
[file1]
INDEXED_EXTRACTIONS = CSV
FIELD_DELIMETER=,
FIELD_QUOTE="
HEADER_FIELD_DELIMETER=,

0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...