Getting Data In

Why is CSV not being indexed by forwarder when input is tcp?

rtcummins
Observer

[tcp-ssl://9515]

disabled=0

index = myindex

connection_host = ip

sourcetype = mysourcetype

_TCP_ROUTING = myindexcluster

 

The above will allow raw events and default fields to be put into the indexer. 

The below allows indexed csv fields (structured) to be put into the indexer.

The props.conf entry for the sourcetype is used by both tcp and disk file input.

I am using identical csv files as data for each.

Why cannot the tcp ingested csv file be indexed by the forwarder and sent to the indexer?

 

 

 

[batch:///data/myfolder]

move_policy = sinkhole

disabled = 0

index= myindex

sourcetype = mysourcetype

crcSalt = <SOURCE>

recursive = false

_TCP_ROUTING = myindexcluster

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...