Splunk Search

Why is data is got getting indexed when we are adding csv file from add data under settings?

SharmaS2
Explorer

Hi,
data is got getting indexed when we are adding csv file from add data under settings .. its events count is showing as 0 ..

Labels (1)
0 Karma

SharmaS2
Explorer

thanks @richgalloway yes add data wizard is completed successfully.. but when we are trying to search through given indexer , its showing no event .. so we check the indexer details in indexer . file size is given as expected as 1 MB but event count is 0 there  ..

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We still don't have much information to determine what the problem might be.  Would you please answer the other two questions I asked in my first reply?

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There could be many explanations, but it's difficult to offer specific solutions with the little information we have.  Did the Add Data wizard complete successfully?  How did you search for the uploaded data?  What time window did you search?

---
If this reply helps you, Karma would be appreciated.

SharmaS2
Explorer

thanks @richgalloway  PFA screen shot..

i am searching between event time stamp only ..

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is the last time I will ask you to please answer the questions in my original reply.  We can't see your screen and don't know anything about your environment or data so it's  up to you to provide information so we can help diagnose the problem.

How did you search for the uploaded data?  Please provide the full SPL with private information masked.  What time window did you use for the search?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...