<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting events for .csv headers in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643661#M16356</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;props.conf:
[sample]
SHOULD_LINEMERGE = false
pulldown_type = true
HEADER_FIELD_LINE_NUMBER = 2
INDEXED_EXTRACTIONS = csv
TIMESTAMP_FIELDS = TimeCreated
KV_MODE = none
category = Structure
disabled = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;inputs.conf:
[monitor://filepath]
disabled = 0
crcSalt = &amp;lt;SOURCE&amp;gt;
index = index2
sourcetype = sample&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've redacted the filepath and changed some names. I'm not currently using any transforms. This is monitoring ~250 csv's that get replaced once a day. It works fine except for the extra events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 14:59:20 GMT</pubDate>
    <dc:creator>R15</dc:creator>
    <dc:date>2023-05-17T14:59:20Z</dc:date>
    <item>
      <title>How to get events for .csv headers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643532#M16348</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I found similar questions but the usual solution of using&amp;nbsp;HEADER_FIELD_LINE_NUMBER did not work.&lt;/P&gt;
&lt;P&gt;My custom csv sourcetype is working fine, except I'm getting an extra event with the column names. Splunk knows they're column names, it's still treating them as fields so the event has Col1=Col1, Col2=Col2 etc. The csv's all start the same, there's an identical line 1 then and identical line 2 which is the column names. After adding&amp;nbsp;HEADER_FIELD_LINE_NUMBER =2 (in props.conf on the forwarder), I'm still getting events with the column names, but now I'm ALSO getting events with just the first line as well. Am I missing something?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 13:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643532#M16348</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-17T13:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643535#M16349</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252191"&gt;@R15&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please provide all the Splunk config for this CSV file (inputs, props, transforms?) that are defined on the UF.&lt;BR /&gt;&lt;BR /&gt;Use the insert/edit code button to format it nicely.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_0-1684284504430.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25401iCD9B72A42CCD32A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_0-1684284504430.png" alt="yeahnah_0-1684284504430.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 00:48:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643535#M16349</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-17T00:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643661#M16356</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;props.conf:
[sample]
SHOULD_LINEMERGE = false
pulldown_type = true
HEADER_FIELD_LINE_NUMBER = 2
INDEXED_EXTRACTIONS = csv
TIMESTAMP_FIELDS = TimeCreated
KV_MODE = none
category = Structure
disabled = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;inputs.conf:
[monitor://filepath]
disabled = 0
crcSalt = &amp;lt;SOURCE&amp;gt;
index = index2
sourcetype = sample&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've redacted the filepath and changed some names. I'm not currently using any transforms. This is monitoring ~250 csv's that get replaced once a day. It works fine except for the extra events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 14:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643661#M16356</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-17T14:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643701#M16361</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252191"&gt;@R15&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks.&amp;nbsp; That configuration looks good to me, so it's a bit strange.&lt;BR /&gt;&lt;BR /&gt;You probably have already done this, but if you have access to the source CSV files, have you opened them with a text editor and confirmed there are no empty or blank lines a the start.&amp;nbsp; Might explain why it works for some files and not others.&lt;BR /&gt;&lt;BR /&gt;If you could provide a redacted example of the first three or so lines of a CSV file, then that may help.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 22:16:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643701#M16361</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-17T22:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643706#M16362</link>
      <description>&lt;P&gt;I do have access and have looked through a few dozen of them. They all appear normal/identical for the first two lines. I can't copy and paste from that environment so I only typed the first few fields of line 2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;#TYPE System.Diagnostics.Eventing.Reader.EventLogRecord
"Message","Id","Version","Qualifiers","Level","Task" &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;They're all Windows event logs with the same fields.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To reiterate, before I was getting all events correctly plus an additional event containing only line 2. After adding&amp;nbsp;&lt;SPAN&gt;HEADER_FIELD_LINE_NUMBER = 2, I'm still getting that additional event plus another containing only line 1.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 23:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643706#M16362</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-17T23:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643710#M16363</link>
      <description>&lt;P&gt;Well, you've done everything right, as far as I can tell.&amp;nbsp; It looks like it should work.&lt;BR /&gt;&lt;BR /&gt;Generally, Splunk is pretty good at auto detecting the header field line for inputs like this without specifying&amp;nbsp;HEADER_FIELD_LINE_NUMBER.&amp;nbsp; Another setting you could try is this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;PREAMBLE_REGEX = ^(#TYPE| *$)&lt;/LI-CODE&gt;&lt;P&gt;It should ignore any header lines that have start with #TYPE or are blank/empty.&amp;nbsp; Remove&amp;nbsp;HEADER_FIELD_LINE_NUMBER and ensure the UF is restarted.&lt;BR /&gt;&lt;BR /&gt;Hope that helps&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 00:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/643710#M16363</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-18T00:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644185#M16384</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;I've added that line and removed&amp;nbsp;&lt;SPAN&gt;HEADER_FIELD_LINE_NUMBER but to no effect.&lt;BR /&gt;&lt;BR /&gt;You mentioned restarting the forwarder which I haven't been doing as I don't have permissions. I've been pushing these changes from a deployment server (which I have full access/control).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 00:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644185#M16384</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-23T00:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644187#M16385</link>
      <description>&lt;P&gt;On a SPlunk universal forwarder agent you'll need a restart to pick up any changes, which would help explain why this is not working.&lt;BR /&gt;&lt;BR /&gt;If you do not have access this a restart can still be done via the deployment server, under the Apps tab, where you need to ensure the Restart Splunkd checkbox is ticked for the deployed app.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_0-1684800474013.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25506iBDD059D511BE4D3E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_0-1684800474013.png" alt="yeahnah_0-1684800474013.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you have access to the _internal index you can check for a restart of the agent with the following search&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;index=_internal sourcetype=splunkd host=&amp;lt;your host&amp;gt; My GUID&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hopefully, you'll see some positive changes once this is done.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 00:13:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644187#M16385</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-23T00:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644276#M16395</link>
      <description>&lt;P&gt;I've checked and that box was already ticked.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I ran that search and there are events when I made changes yesterday and last week.&lt;/P&gt;&lt;P&gt;Are we at a dead end?&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 15:43:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644276#M16395</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-23T15:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644387#M16407</link>
      <description>&lt;P&gt;Can you confirm the version of Splunk universal forwarder agent you are using.&amp;nbsp; &amp;nbsp;Maybe it is an older version and the props.conf settings do no work on it.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 03:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644387#M16407</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-24T03:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644434#M16415</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;One way to make onboarding / debugging much easier is install splunk on your own laptop and then use that css sample with it. Just add data with Settings -&amp;gt; Add Data and then try to change those options as needed. When you are happy with props &amp;amp; transforms you just copy those to your real app into DS and then deploy those.&lt;/P&gt;&lt;P&gt;On macOS with Splunk 9.0.4.1this works correctly with these settings&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ csv ]
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
KV_MODE=none
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true
HEADER_FIELD_LINE_NUMBER=2
MAX_DAYS_AGO=9999&lt;/LI-CODE&gt;&lt;P&gt;MAX_DAYS_AGO is not needed, I just added it with TimeCreated values like&amp;nbsp;11111111111 to work.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 09:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644434#M16415</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-05-24T09:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644527#M16430</link>
      <description>&lt;P&gt;I did some testing before implementing by starting to add a sample directly to an indexer, and the events preview looked good. There were no extra events.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I will push your sourcetype code and report back (I'll just replace MAX_DAYS_AGO=9999 with TIMESTAMP_FIELDS=TimeCreated).&lt;/P&gt;&lt;P&gt;Our forwarders are running 8.0.6&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 17:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644527#M16430</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-24T17:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644564#M16433</link>
      <description>&lt;P&gt;The Splunk docs indicate it all should work, but maybe the Splunk UF and Splunk Enterprise are not aligned at this version.&amp;nbsp; You could try a Support ticket but Splunk would probably want a supported UF version installed to do anything.&lt;BR /&gt;&lt;BR /&gt;Like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;and you said, it works fine when testing the config on Splunk Enterprise (v8.2.7 for me).&amp;nbsp; &amp;nbsp;The only other thing I can think of, is there is a small mistake in the config you have pushed out.&amp;nbsp; Double/triple check the sourcetype names match.&amp;nbsp; Maybe try adding a new stanza entry, using [source::&amp;lt;you file&amp;gt;], which has a higher precedence than sourcetype stanzas, and see if that works.&lt;BR /&gt;&lt;BR /&gt;It gets pretty hard to help when you are not able to see the environment and the real configs in use.&amp;nbsp; All I can say from what I seen, is that it should be working, so either it's a versioning issue with the Splunk UF (can it be upgraded) or the config has a small mistake.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 23:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644564#M16433</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-24T23:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644666#M16445</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;I have confirmed the forwarder and indexer are both on 8.0.6. We intend to upgrade but I'd be lucky if it's by the end of the year.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;With no sourcetype or with the default csv sourcetype the events do not have proper timestamps. So I know my sourcetype is definitely being applied, and it works, it's just throwing out these junk events as well for some reason. I replaced it with the code from&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;and got the same result. I will turn to support for further troubleshooting. Thank you both for your time!&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 17:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644666#M16445</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-05-25T17:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Getting events for .csv headers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644681#M16446</link>
      <description>&lt;P&gt;Good luck and if you do find out why it's not working for you then it would be good to update this question with the answer.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 21:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/644681#M16446</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-05-25T21:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to get events for .csv headers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670049#M17944</link>
      <description>&lt;P&gt;As an added note to this forum I am having the same exact issue. Interestingly enough, like you I had&amp;nbsp;&lt;SPAN&gt;HEADER_FIELD_LINE_NUMBER set(in my case it is set to 1). Been ingesting the files for a couple of days and for some reason today it just now started ingesting the headers as an event, though nothing has changed on my end.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 16:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670049#M17944</guid>
      <dc:creator>bookshark13</dc:creator>
      <dc:date>2023-11-28T16:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to get events for .csv headers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670053#M17945</link>
      <description>&lt;P&gt;What version of splunk are you running? We're still on 8, but upgrading to 9 soon™.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 16:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670053#M17945</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-11-28T16:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get events for .csv headers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670061#M17946</link>
      <description>&lt;P&gt;We are running 9.1.2&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 17:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670061#M17946</guid>
      <dc:creator>bookshark13</dc:creator>
      <dc:date>2023-11-28T17:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get events for .csv headers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670213#M17950</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252191"&gt;@R15&lt;/a&gt;Odd question for you but did you run the fillnull command?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 16:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670213#M17950</guid>
      <dc:creator>bookshark13</dc:creator>
      <dc:date>2023-11-29T16:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to get events for .csv headers?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670241#M17954</link>
      <description>&lt;P&gt;No, I don't believe so.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 23:03:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-get-events-for-csv-headers/m-p/670241#M17954</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2023-11-29T23:03:30Z</dc:date>
    </item>
  </channel>
</rss>

