Getting Data In

error during csv index extraction

ebaileytu
Communicator

I have setup a process where a heavy forwarder is ingesting a large number of csv files and the process seems to be working, but I am seeing the following error message for every single csv file

08-26-2016 08:41:19.386 -0500 WARN CsvLineBreaker - CSV StreamId: 2416848287927153596 has empty line. - data_source="/shared/storage_performance/storage/Hitachi/xxxxx/PhyLDEV_dat/xxxxx_8_26_2016_0746_PHY_Long_LDEV_1-7_0.csv", data_host="xxxxx", data_sourcetype="hitachi_perf"

Any idea what this means? I do see a blank line at the end of each CSV file. The data is being extracted as desired and the only issue I see other than the error message is the process is not very fast.

I am using 6.3.3

inputs.conf

[batch:///shared/storage_performance/storage/Hitachi]
disabled = false
host_segment = 5
index = storage
sourcetype = hitachi_perf
move_policy = sinkhole
crcSalt =
recursive = true
whitelist = .csv$

props.conf

[hitachi_perf]
category = Custom
description = Corp Hitachi Performance Data
pulldown_type = 1
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
TZ = GMT
disabled = false

Thanks in advance!

0 Karma
1 Solution

jpolcari
Communicator

That error is merely telling you that it found a blank line within the CSV file. Notice it is just a WARN. It appears the file is still importing without issue. I think you can safely ignore these warnings.

View solution in original post

0 Karma

jpolcari
Communicator

That error is merely telling you that it found a blank line within the CSV file. Notice it is just a WARN. It appears the file is still importing without issue. I think you can safely ignore these warnings.

0 Karma

ebaileytu
Communicator

ok - what I was thinking but nice to get some confirmation.

0 Karma

ATB_Jesse
Explorer

Is it possible to suppress the error per-sourcetype so as not to clutter the logs?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...