Splunk Search

Index a small file (2 KB)

rayar
Contributor

Hi
I need to index a small file (2KB) (on Heavy Forwarder )
the file is not indexed

[monitor://\raanana\Tabi4Splunk\TABLEAU_integration_csv\MIS.csv]
disabled = false
index = penetrationtest_mis
sourcetype = csv_current_time
crcSalt =

Tags (1)
0 Karma

rayar
Contributor

looks like the issue got resolved with the below configuration

[monitor://\raanana\Tabi4Splunk\TABLEAU_integration_csv\MIS.csv]
disabled = false
index = penetrationtest_mis
sourcetype = csv_current_time
crcSalt =
initCrcLength = 1024

thanks a lot

0 Karma

PavelP
Motivator

Please don't forget to select "Accept as a solution" if this reply resolves your query!

0 Karma

PavelP
Motivator

if the file has a large header then CRC can be an issue. You may need to set initCrcLength.

try to run this command in elevated command prompt (as admin):

c:\programfiles\splunk\bin\splunk.exe list inputstatus
0 Karma

HiroshiSatoh
Champion

I think it's not about file size, it's about file specifications.
Can you upload a sample file?
Do you know the specifications of the update?

0 Karma

rayar
Contributor

i have copied the same data few time (file size 12 kb) in the same file and it indexed properly

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...