Splunk Search

Metric Index problem with null values

drezanka
Explorer

I am running Splunk Enterprise 8.0.1 monitoring files with a universal forwarder and putting info from csv files into a metric index using logs to metrics through props.conf and transforms.conf. Most of the monitored files are working as expected but one is not showing up in the metric index and I cannot find any errors about it in splunkd.log or metrics.log.

This file occasionally has the last entry empty. Here is an example of the data:
one,1,100
two,2,200
three,3,
four,4,400

The value in column three is set to be a dimension for the metric data. It is actually a key variable and I need to be able to track it. Does anyone know if the missing value is causing the data not to import into my metric index and if so, how to fix it? Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...