The Upload page lets you upload a file to your instance from your computer. You can upload files by clicking the "Upload" button from Splunk Home in Splunk Web.
Note the following:
- While you can upload any file to Splunk Enterprise or Splunk Cloud Platform, Windows Event Log (.evt) and Windows Event Log XML (.evtx) files that you exported from another Windows machine don't work with the upload feature. This is because these files contain information that is specific to the Windows machine that generated them. Machines that do not generate these files can't process them in their unaltered form. See Index exported event log files for more information about the constraints for working with these kinds of files.
- The Splunk Add-On for Sysmon is not supported for use with data loaded using the Upload Data functionality. For best results, use one of the supported options to collect Windows Sysmon events as described in the Splunk Add-On for Sysmon manual.
The Upload page
- Upload data through one of the following methods on this page:
- Select Add Data, which is found in either the Settings dropdown or the Splunk Enterprise homepage.
- Select Upload, and then select your data file.
- then loads the file and processes it, depending on what type of file it is.
- After the file has completed loading, click Next.
How do you want to add data?
This documentation applies to the following versions of Splunk Cloud Platform™: 9.1.2312, 8.2.2202, 8.2.2112, 8.2.2201, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305 (latest FedRAMP release), 9.1.2308