Getting Data In

Why my csv file indexed only the header ?

mah
Builder

Hi, 

I have a script which output a csv file : 

id,name,env,start,end

1234,test,[env]:dev,2020-12-31 18:07,2020-12-31 19:07

The first line is the header and ALL lines in file must be reindexed each time there is a modification (adding or a suppression). 

I have an inputs.conf like this : 

[monitor:///opt/splunk/etc/apps/my_app/bin/my_csv.csv]
index = test
sourcetype = st
disabled = 0
initCrcLength = 3000

I have a props.conf like : 

[st]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

The indexation is really weird : it actually index only the header :

mah_0-1609348826223.png

Can you help me please ?

Thank a lot.

 

Labels (2)
Tags (1)
0 Karma

FlorianScho
Path Finder

Hi @mah,

did you fixed the problem? Im currently facing the same.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...