Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to configure Splunk to read a csv file from a universal forwarder?

$
0
0
Hi, I have one csv file at location /apps/data_splunk/.csv And this CSV file has data like below JAN-18 | 31-JAN-2018 | -1 | 1 | 31-JAN-18 | 01-FEB-18 | 727 JAN-18 | 01-FEB-2018 | 1 | 1 | 01-FEB-18 | 02-FEB-18 | 751 JAN-18 | 02-FEB-2018 | 2 | 1 | 02-FEB-18 | 02-FEB-18 | 342 JAN-18 | 06-FEB-2018 | 4 | 1 | 06-FEB-18 | 06-FEB-18 | 323 I want to forward this data to my splunk. Here is what I have done, but it's not working. I have these setup on the Splunk UF server. Inputs.conf [monitor://data_splunk/.csv] disabled = false index = _idx2 sourcetype = mycsvfileData Props.conf [mycsvfileData] INDEXED_EXTRACTIONS = csv SHOULD_LINEMERGE = false NO_BINARY_CHECK = true KV_MODE = none category = Structured FIELD_DELIMITER = | Please let me know, what I am doing wrong. Please suggest the better way. Thanks in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>