Splunk Search

How to upload multiple files in Splunk? Is it possible to upload multiple files like 100 1MB files in Splunk at the same time?

swati_sharma
New Member

How to upload multiple files in the Splunk?

Tags (3)
0 Karma

supunsap
New Member

If you want to upload multiple files in Splunk, you can zip file and browse it

0 Karma

jeffland
SplunkTrust
SplunkTrust

Do you want to upload them from the Web UI? I don't think that would work with the wizard there.

However, if you can, simply move your files to the instance running splunk and add a file monitor to those files, indexing them only once (not continuously).

0 Karma

swati_sharma
New Member

Is there no way to upload the directory to the splunk likewise we uploaded files?

0 Karma

csnidsplunk
Explorer

Why dont you put them all in a zip. Keep under 500 MB and u have your one file. 😉 Worked for me.

swati_sharma
New Member

yes, through Web UI, If I am not wrong, you want to say that we can't upload directory having 1MB*100files to the splunk.
Is there any other way by which we can upload the directory to the splunk.?

0 Karma

jeffland
SplunkTrust
SplunkTrust

Why don't you try either the oneshot from the cli, or if you like to work with the ui setting a monitor to that directory, indexing once? That does exactly what you need.

How else would you "upload" a directory? The "Add Data" wizard handles individual files, I don't see how you would apply it to more than one file.

0 Karma

swati_sharma
New Member

Please reply as soon as possible. whatever it would be.

0 Karma

bmacias84
Champion

I would use oneshot from the cli. The web interface doesn't support multiple files. Just run oneshot from any forwarder configured to send to your indexer.

http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/MonitorfilesanddirectoriesusingtheCLI

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...