Getting Data In

Why is CSV not being indexed by forwarder when input is tcp?

rtcummins
Observer

[tcp-ssl://9515]

disabled=0

index = myindex

connection_host = ip

sourcetype = mysourcetype

_TCP_ROUTING = myindexcluster

 

The above will allow raw events and default fields to be put into the indexer. 

The below allows indexed csv fields (structured) to be put into the indexer.

The props.conf entry for the sourcetype is used by both tcp and disk file input.

I am using identical csv files as data for each.

Why cannot the tcp ingested csv file be indexed by the forwarder and sent to the indexer?

 

 

 

[batch:///data/myfolder]

move_policy = sinkhole

disabled = 0

index= myindex

sourcetype = mysourcetype

crcSalt = <SOURCE>

recursive = false

_TCP_ROUTING = myindexcluster

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...