Splunk Search

Unable to input zipped csv files from .gz

hethaishibk
New Member

Hi All,
I am unable to index .gz files which has csv file. Can you guys please help
04-16-2019 03:11:28.982 -0400 INFO ArchiveProcessor - reading path=/guard_datamart/DMv2_EXP_BUFF_USAGE_20190415060000.gz (seek=0 len=4210)
04-16-2019 03:11:29.027 -0400 WARN FileClassifierManager - The file '/guard_datamart/DMv2
EXP_BUFF_USAGE_20190415060000' is invalid. Reason: binary
04-16-2019 03:11:29.040 -0400 WARN FileClassifierManager - The file '/guard_datamart/DMv2
EXP_BUFF_USAGE_20190415060000' is invalid. Reason: binary
04-16-2019 03:11:29.040 -0400 INFO ArchiveProcessor - Finished processing file '/guard_datamart/DMv2
_EXP_BUFF_USAGE_20190415060000.gz', removing from stats

Tags (1)
0 Karma

codebuilder
Influencer

Based on the output you provided, the files within your .gz do not appear to have a file extension. Splunk therefore interprets those as binary files and will not attempt to ingest them.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
Influencer

Did this resolve your issue?

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

hethaishibk
New Member

please help on the above query

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...