Splunk Enterprise

Splunk UF - The file is invalid, cannot open

NoSpaces
Contributor

Hello to everyone!
I have an UF installed on a MS file server
Our Unified Communications Manager sends CDR and CMR files to this file server via SFTP
Often enough, I see error messages, as you see in the screenshot (UF cannot read the file)
The most strange thing is that all information from such files is successfully read
What is wrong with my UF settings?
Or maybe this is not UF?

props.conf

[ucm_file_cdr]
SHOULD_LINEMERGE = False
INDEXED_EXTRACTIONS = csv 
TIMESTAMP_FIELDS = dateTimeOrigination
BREAK_ONLY_BEFORE_DATE = False
MAX_TIMESTAMP_LOOKAHEAD = 60
initCrcLength = 1500
ANNOTATE_PUNCT = false
TRANSFORMS-no_column_headers = no_column_headers

[ucm_file_cmr]
SHOULD_LINEMERGE = False
INDEXED_EXTRACTIONS=csv
TIMESTAMP_FIELDS = dateTimeOrigination
BREAK_ONLY_BEFORE_DATE = False
MAX_TIMESTAMP_LOOKAHEAD = 13
initCrcLength = 1000
ANNOTATE_PUNCT = false
TRANSFORMS-no_column_headers = no_column_headers

 

transforms.conf

[no_column_headers]
REGEX = ^INTEGER\,INTEGER\,INTEGER.*$
DEST_KEY = queue
FORMAT = nullQueue

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...