Getting Data In

Why is CSV not being indexed by forwarder when input is tcp?

rtcummins
Observer

[tcp-ssl://9515]

disabled=0

index = myindex

connection_host = ip

sourcetype = mysourcetype

_TCP_ROUTING = myindexcluster

 

The above will allow raw events and default fields to be put into the indexer. 

The below allows indexed csv fields (structured) to be put into the indexer.

The props.conf entry for the sourcetype is used by both tcp and disk file input.

I am using identical csv files as data for each.

Why cannot the tcp ingested csv file be indexed by the forwarder and sent to the indexer?

 

 

 

[batch:///data/myfolder]

move_policy = sinkhole

disabled = 0

index= myindex

sourcetype = mysourcetype

crcSalt = <SOURCE>

recursive = false

_TCP_ROUTING = myindexcluster

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...