Getting Data In

Why is Splunk unable to index a converted text file?

Abilan1
Path Finder

Hi ,

I have saved the outlook file as a text fie and placed that file into a Splunk monitoring folder. Splunk is just indexing only the 1st line of that text file and for some other converted text files, it is not even indexing a single line. I would like to know if Splunk supports these kind of files or any other way to do this?

Thanks!

Tags (3)
0 Karma

Runals
Motivator

I'd look in the internal logs (index=_internal) to see if you can get info from it. Might have to look for things like directory path elements, file name, etc.

0 Karma

asimagu
Builder

Open it with Notepad++ for example and check that the encoding is UTF-8

0 Karma

Abilan1
Path Finder

Hi,

I have checked the file type, it is UTF-8 encoding. Splunk is indexing only 1st line of that file.

Thanks!

0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...