I'm trying to manually upload some text files, with a .txt extension, to Splunk.  I went through the UI to Upload and index a file, and Splunk indicates that it has successfully indexed it, but the file cannot be found in searches.
  Any advice as to what I might do differently or troubleshooting steps would be lovely.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi mcomfurf,
here are some typical troubleshooting tips:
index=main which is the default or what ever index name you have?index=_internal source=*splunkd.log on the indexer for any error related to the this txt filehope this helps ...
cheers, MuS
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi mcomfurf,
here are some typical troubleshooting tips:
index=main which is the default or what ever index name you have?index=_internal source=*splunkd.log on the indexer for any error related to the this txt filehope this helps ...
cheers, MuS
Thanks, MuS, that was just the ticket. The text files were binary & couldn't be processed after ingestion. Too bad the Splunk UI does not warn you of this when you upload the file.
I've tried searching for the file name as source, and for the sourcetype assigned to it.
 
					
				
		
What have you tried in searches?
