Splunk Search

Why is data is got getting indexed when we are adding csv file from add data under settings?

SharmaS2
Explorer

Hi,
data is got getting indexed when we are adding csv file from add data under settings .. its events count is showing as 0 ..

Labels (1)
0 Karma

SharmaS2
Explorer

thanks @richgalloway yes add data wizard is completed successfully.. but when we are trying to search through given indexer , its showing no event .. so we check the indexer details in indexer . file size is given as expected as 1 MB but event count is 0 there  ..

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We still don't have much information to determine what the problem might be.  Would you please answer the other two questions I asked in my first reply?

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There could be many explanations, but it's difficult to offer specific solutions with the little information we have.  Did the Add Data wizard complete successfully?  How did you search for the uploaded data?  What time window did you search?

---
If this reply helps you, Karma would be appreciated.

SharmaS2
Explorer

thanks @richgalloway  PFA screen shot..

i am searching between event time stamp only ..

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is the last time I will ask you to please answer the questions in my original reply.  We can't see your screen and don't know anything about your environment or data so it's  up to you to provide information so we can help diagnose the problem.

How did you search for the uploaded data?  Please provide the full SPL with private information masked.  What time window did you use for the search?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...