Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I read a tgz file into Splunk?

$
0
0
According to a book (**Splunk Essentials By: Betsy Page Sigman**) I recently read on Splunk, Splunk can read in data from basically all types of files containing clear data, or as they put it, any data. Splunk can also decompress the following types of files: *tar, gz, bz2, tar.gz, tgz, tbz, tbz2, zip, and z* along with many other formats. If this is true, how does it decompress the data? Specifically, if I am using "Add Data" within the manager can it first decompress a tgz file and then input it or do I need to decompress it first? I have a tgz file I am trying to input that is 1.08GB in size. However, every time I browse to it and try to input the file I get a message that the file is over 500MB and Splunk will not accept it. Can someone here help me solve this problem?

Viewing all articles
Browse latest Browse all 47296

Trending Articles