I have created a new index and when i search that in search head its not working.
[monitor:///apps/splunk/var/run/splunk/fprsbatch.csv]
host = vc2cmmkb019694n.fmr.com
source = bhav
sourcetype = bhav_stype
index = transactions
[source::bhav]
REPORT-transactions = fprsbatch_csv
MAX_DAYS_AGO = 10000
SHOULD_LINEMERGE = False
[fprsbatch_csv]
DELIMS = ","
FIELDS = "ODATE","0TIME","TRANS","AMOUNT"
I have restarted the server once (its a free version)
FOund out the issue. there were ^M chars in the input file