Splunk Enterprise

Upload CSV file

wahluf
Explorer

I am a beginner learning splunk. I have data that I want to read through the splunk, it is firewall data with a size of 2.7 gb. In the free enterprise version, the maximum data upload from a computer is 500 MB. What is the solution so that I can still process my large firewall data?

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
0 Karma

to4kawa
Ultra Champion
0 Karma

to4kawa
Ultra Champion

There is a limit to the amount of data you can import in a day.
If you have a date in your log, why don't you break it down into several days?

0 Karma

wahluf
Explorer

2.7 GB of firewall log data in one day. In your opinion, what tool do you recommend to use to split a .csv file into smaller pieces.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...