Splunk Search

help need with add oneshot CLI

desi
New Member

Hello, i am trying to run add oneshot from cli but keep getting following error:

C:\Program Files\Splunk\bin>splunk add oneshot "C:\csv\test.csv" -sourcetype csv -index csv_index -source test -auth admin:changeme

In handler 'oneshotinput': Only one "name" parameter can be specified.

help please

thanks

Tags (2)
0 Karma

Steve_G_
Splunk Employee
Splunk Employee

See this topic in the docs for information on the "rename-source" parameter:

http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI

bwooden
Splunk Employee
Splunk Employee

You can't name a source in oneshot (as it is already named as the file to add). Fortunately, a workaround discussion already exists: how-do-you-override-source-on-a-oneshot

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...