Getting Data In

Why is CSV not being indexed by forwarder when input is tcp?

rtcummins
Observer

[tcp-ssl://9515]

disabled=0

index = myindex

connection_host = ip

sourcetype = mysourcetype

_TCP_ROUTING = myindexcluster

 

The above will allow raw events and default fields to be put into the indexer. 

The below allows indexed csv fields (structured) to be put into the indexer.

The props.conf entry for the sourcetype is used by both tcp and disk file input.

I am using identical csv files as data for each.

Why cannot the tcp ingested csv file be indexed by the forwarder and sent to the indexer?

 

 

 

[batch:///data/myfolder]

move_policy = sinkhole

disabled = 0

index= myindex

sourcetype = mysourcetype

crcSalt = <SOURCE>

recursive = false

_TCP_ROUTING = myindexcluster

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...