PAY SPECIAL ATTENTION TO THE CASING (upper/lower/mixed) OF THE SOURCETYPE EVERYWHERE IT IS USED!
Try these:
inputs.conf:
[monitor:///$SPLUNK_HOME/etc/apps/search/lookups/ControlUp_Computers_05_14_2016_15_00_20.csv]
sourcetype=ControlUPComputer
index = main
props.conf
[ControlUPComputer]
DATETIME_CONFIG = CURRENT
INDEXED_EXTRACTIONS = CSV
HEADER_FIELD_LINE_NUMBER = 2
HEADER_FIELD_DELIMITER = ,
FIELD_QUOTE = "
FIELD_DELIMITER = ,
Put these both on your forwarder (YES, your forwarder) and restart the splunk instances there. Events indexed after the restart will be correct. Your big problem was the casing mismatch.
... View more