Splunk Search

Why is data is got getting indexed when we are adding csv file from add data under settings?

SharmaS2
Explorer

Hi,
data is got getting indexed when we are adding csv file from add data under settings .. its events count is showing as 0 ..

Labels (1)
0 Karma

SharmaS2
Explorer

thanks @richgalloway yes add data wizard is completed successfully.. but when we are trying to search through given indexer , its showing no event .. so we check the indexer details in indexer . file size is given as expected as 1 MB but event count is 0 there  ..

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We still don't have much information to determine what the problem might be.  Would you please answer the other two questions I asked in my first reply?

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There could be many explanations, but it's difficult to offer specific solutions with the little information we have.  Did the Add Data wizard complete successfully?  How did you search for the uploaded data?  What time window did you search?

---
If this reply helps you, Karma would be appreciated.

SharmaS2
Explorer

thanks @richgalloway  PFA screen shot..

i am searching between event time stamp only ..

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is the last time I will ask you to please answer the questions in my original reply.  We can't see your screen and don't know anything about your environment or data so it's  up to you to provide information so we can help diagnose the problem.

How did you search for the uploaded data?  Please provide the full SPL with private information masked.  What time window did you use for the search?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...