Splunk Search

Why is data is got getting indexed when we are adding csv file from add data under settings?

SharmaS2
Explorer

Hi,
data is got getting indexed when we are adding csv file from add data under settings .. its events count is showing as 0 ..

Labels (1)
0 Karma

SharmaS2
Explorer

thanks @richgalloway yes add data wizard is completed successfully.. but when we are trying to search through given indexer , its showing no event .. so we check the indexer details in indexer . file size is given as expected as 1 MB but event count is 0 there  ..

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We still don't have much information to determine what the problem might be.  Would you please answer the other two questions I asked in my first reply?

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There could be many explanations, but it's difficult to offer specific solutions with the little information we have.  Did the Add Data wizard complete successfully?  How did you search for the uploaded data?  What time window did you search?

---
If this reply helps you, Karma would be appreciated.

SharmaS2
Explorer

thanks @richgalloway  PFA screen shot..

i am searching between event time stamp only ..

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is the last time I will ask you to please answer the questions in my original reply.  We can't see your screen and don't know anything about your environment or data so it's  up to you to provide information so we can help diagnose the problem.

How did you search for the uploaded data?  Please provide the full SPL with private information masked.  What time window did you use for the search?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...