Getting Data In

Uploaded files not indexed

Path Finder

I'm trying to manually upload some text files, with a .txt extension, to Splunk. I went through the UI to Upload and index a file, and Splunk indicates that it has successfully indexed it, but the file cannot be found in searches.
Any advice as to what I might do differently or troubleshooting steps would be lovely.

Tags (1)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

Hi mcomfurf,

here are some typical troubleshooting tips:

  • Do you search the correct time range - try all time?
  • Do you search the correct index - try index=main which is the default or what ever index name you have?
  • Do you have permission to search this index?
  • search index=_internal source=*splunkd.log on the indexer for any error related to the this txt file

hope this helps ...

cheers, MuS

View solution in original post

SplunkTrust
SplunkTrust

Hi mcomfurf,

here are some typical troubleshooting tips:

  • Do you search the correct time range - try all time?
  • Do you search the correct index - try index=main which is the default or what ever index name you have?
  • Do you have permission to search this index?
  • search index=_internal source=*splunkd.log on the indexer for any error related to the this txt file

hope this helps ...

cheers, MuS

View solution in original post

Path Finder

Thanks, MuS, that was just the ticket. The text files were binary & couldn't be processed after ingestion. Too bad the Splunk UI does not warn you of this when you upload the file.

0 Karma

Path Finder

I've tried searching for the file name as source, and for the sourcetype assigned to it.

0 Karma

Legend

What have you tried in searches?

0 Karma