Splunk Search

Metric Index problem with null values

drezanka
Explorer

I am running Splunk Enterprise 8.0.1 monitoring files with a universal forwarder and putting info from csv files into a metric index using logs to metrics through props.conf and transforms.conf. Most of the monitored files are working as expected but one is not showing up in the metric index and I cannot find any errors about it in splunkd.log or metrics.log.

This file occasionally has the last entry empty. Here is an example of the data:
one,1,100
two,2,200
three,3,
four,4,400

The value in column three is set to be a dimension for the metric data. It is actually a key variable and I need to be able to track it. Does anyone know if the missing value is causing the data not to import into my metric index and if so, how to fix it? Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...