Is there any limit on data being indexed from a csv file which is monitored from a remote machine with Splunk UF installed ? The file has over 1 million records and I am seeing less events than expected. Some of the fields with time in it dates back to early 2000s so I have added MAX_DAYS_AGO parameter but not sure why I am not seeing all the 1M records.
↧