Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I configure Splunk to properly index my file in production?

$
0
0
I have a file in production that appears to not be indexed as running a search for `index=` returns no results. The file has no header and has the following field format. 2016-04-05 02:51:05.4457|Error|Error receiving response: Connection timeout I have tested this file on my locally installed instance by replacing the first pipe with a space as to isolate the time field as such. 2016-04-05 02:51:05.4457 Error|Error receiving response: Connection timeout This worked on my local instance. However, I am unable to modify the production file. Is there a way to mimic this change through settings to work on the production file?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>