Getting Data In

required conf files to monitor csv data frequently

pavithra
Explorer

Hi All,

 

Please provide conf files ( inputs.conf,props.con,outputs.conf) to index the below format data on daily basis

pavithra_0-1723178237388.png

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What have you tried so far and how does it fail to meet your expectations?

0 Karma

pavithra
Explorer

its not extracting the whole data

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You didn't say what have you tried so far. Maybe you have some small easily fixable mistake in your configs or maybe your approach is completely wrong. Show us what you've got.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pavithra ,

to answer to your question I need more information:

  • filename,
  • path,
  • column separator,
  • sourcetype,
  • index.

Anyway, supponing that the file is called "myfile2024-08-09.csv" and that the path is "/opt/data/files", you could use these:

inputs.conf

[monitor:///opt/data/files/myfile*.csv]
disabled = 0
index = your_index
sourcetype = your_sourcetype
host = your_host

Then you should also configure props.conf for INDEXED_EXTRACTIONS = CSV.

Ciao.

Giuseppe

 

0 Karma

pavithra
Explorer

Hi ,
Thanks for the response! Please find the details below

  • filename -BackupJobSummaryReport_2024-07-07-08-00-06 ( it will be in incremental order based on date)
  • path - C:\Users\_svcAPACCommVault01\OneDrive - Lendlease\Desktop\csv\*.csv
  • column separator,- 

     Client,Host Name,Total Jobs,Completed,Completed with errors,Completed with warnings,Killed,Unsuccessful,Running,Delayed,No Run,No Schedule,Committed,Size of Application,Compression Rate,Data Written,(Space Saving Percentage),Start Time,End Time,Protected Objects,Failed Objects,Failed Folders

  • sourcetype - backup
  • index - acn_lendlease_commvault



0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pavithra 

adding your information to the below inputs.conf:

[monitor://C:\Users\_svcAPACCommVault01\OneDrive - Lendlease\Desktop\csv\*.csv]
disabled = 0
sourcetype = backup
index = acn_lendlease_commvault
host = your_host

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...