Getting Data In

Uploaded files not indexed

mcomfurf
Path Finder

I'm trying to manually upload some text files, with a .txt extension, to Splunk. I went through the UI to Upload and index a file, and Splunk indicates that it has successfully indexed it, but the file cannot be found in searches.
Any advice as to what I might do differently or troubleshooting steps would be lovely.

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi mcomfurf,

here are some typical troubleshooting tips:

  • Do you search the correct time range - try all time?
  • Do you search the correct index - try index=main which is the default or what ever index name you have?
  • Do you have permission to search this index?
  • search index=_internal source=*splunkd.log on the indexer for any error related to the this txt file

hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi mcomfurf,

here are some typical troubleshooting tips:

  • Do you search the correct time range - try all time?
  • Do you search the correct index - try index=main which is the default or what ever index name you have?
  • Do you have permission to search this index?
  • search index=_internal source=*splunkd.log on the indexer for any error related to the this txt file

hope this helps ...

cheers, MuS

mcomfurf
Path Finder

Thanks, MuS, that was just the ticket. The text files were binary & couldn't be processed after ingestion. Too bad the Splunk UI does not warn you of this when you upload the file.

0 Karma

mcomfurf
Path Finder

I've tried searching for the file name as source, and for the sourcetype assigned to it.

0 Karma

lguinn2
Legend

What have you tried in searches?

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...