Getting Data In

Why is CSV not being indexed by forwarder when input is tcp?

rtcummins
Observer

[tcp-ssl://9515]

disabled=0

index = myindex

connection_host = ip

sourcetype = mysourcetype

_TCP_ROUTING = myindexcluster

 

The above will allow raw events and default fields to be put into the indexer. 

The below allows indexed csv fields (structured) to be put into the indexer.

The props.conf entry for the sourcetype is used by both tcp and disk file input.

I am using identical csv files as data for each.

Why cannot the tcp ingested csv file be indexed by the forwarder and sent to the indexer?

 

 

 

[batch:///data/myfolder]

move_policy = sinkhole

disabled = 0

index= myindex

sourcetype = mysourcetype

crcSalt = <SOURCE>

recursive = false

_TCP_ROUTING = myindexcluster

Tags (3)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...