<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexing from a .csv file into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601013#M104734</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225099"&gt;@ramganeshn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;csv files are one of the most used data souces in Splunk!&lt;/P&gt;&lt;P&gt;Answering to your questions:&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;see monitor files and directory input and use for your csv files the sourcetype "csv" or use a your own custom sourcetype where there's the option INDEXED_EXTRACTIONS=CSV&lt;/P&gt;&lt;P&gt;if you try to ingest one csv file using the guided UI procedure [Settings -- Add Data-- upload files] you can find an help in sourcetype definition.&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;there isn't any prerequisite, my hint is only to avoid field names with spaces or special chars,&lt;/P&gt;&lt;P&gt;3)&lt;/P&gt;&lt;P&gt;there isn't any limitation not&amp;nbsp; already present in the csv file itself, maybe the limit of 500 MB but a csv file of 500 mg is a mad idea!&lt;/P&gt;&lt;P&gt;4)&lt;/P&gt;&lt;P&gt;there isn't any prerequisite, my hint is only to avoid field names with spaces or special chars,&lt;/P&gt;&lt;P&gt;5)&lt;/P&gt;&lt;P&gt;&lt;A href="https://hurricanelabs.com/splunk-tutorials/ingesting-a-csv-file-into-splunk/" target="_blank"&gt;https://hurricanelabs.com/splunk-tutorials/ingesting-a-csv-file-into-splunk/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-can-I-configure-Splunk-to-read-a-csv-file-from-a-universal/m-p/170522" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-can-I-configure-Splunk-to-read-a-csv-file-from-a-universal/m-p/170522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jun 2022 11:17:46 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-06-08T11:17:46Z</dc:date>
    <item>
      <title>Questions about Indexing from a .csv file into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601012#M104733</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a few queries regarding data ingestion from a .csv file. I am interested in knowing the following:&lt;/P&gt;
&lt;P&gt;1. What is the most optimal way to bring the data from a .csv file into Splunk?&lt;/P&gt;
&lt;P&gt;2. Are there any pre-requisites to be satisfied before indexing a .csv file?&lt;/P&gt;
&lt;P&gt;3. Are there any limitations in indexing data from a .csv file?&lt;/P&gt;
&lt;P&gt;4. Are there any restrictions in indexing data from a .csv file (maximum file size allowed, maximum rows or maximum columns that can be placed in a single .csv file, maximum number of the file allowed, etc.)&lt;/P&gt;
&lt;P&gt;5. Is there any Splunk documentation available about this requirement? If so, please share the link for the same.&lt;/P&gt;
&lt;P&gt;Thanks much!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 15:39:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601012#M104733</guid>
      <dc:creator>ramganeshn</dc:creator>
      <dc:date>2022-06-08T15:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing from a .csv file into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601013#M104734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225099"&gt;@ramganeshn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;csv files are one of the most used data souces in Splunk!&lt;/P&gt;&lt;P&gt;Answering to your questions:&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;see monitor files and directory input and use for your csv files the sourcetype "csv" or use a your own custom sourcetype where there's the option INDEXED_EXTRACTIONS=CSV&lt;/P&gt;&lt;P&gt;if you try to ingest one csv file using the guided UI procedure [Settings -- Add Data-- upload files] you can find an help in sourcetype definition.&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;there isn't any prerequisite, my hint is only to avoid field names with spaces or special chars,&lt;/P&gt;&lt;P&gt;3)&lt;/P&gt;&lt;P&gt;there isn't any limitation not&amp;nbsp; already present in the csv file itself, maybe the limit of 500 MB but a csv file of 500 mg is a mad idea!&lt;/P&gt;&lt;P&gt;4)&lt;/P&gt;&lt;P&gt;there isn't any prerequisite, my hint is only to avoid field names with spaces or special chars,&lt;/P&gt;&lt;P&gt;5)&lt;/P&gt;&lt;P&gt;&lt;A href="https://hurricanelabs.com/splunk-tutorials/ingesting-a-csv-file-into-splunk/" target="_blank"&gt;https://hurricanelabs.com/splunk-tutorials/ingesting-a-csv-file-into-splunk/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-can-I-configure-Splunk-to-read-a-csv-file-from-a-universal/m-p/170522" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-can-I-configure-Splunk-to-read-a-csv-file-from-a-universal/m-p/170522&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 11:17:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601013#M104734</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-08T11:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about Indexing from a .csv file into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601740#M104829</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;Giuseppe!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 13:36:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601740#M104829</guid>
      <dc:creator>ramganeshn</dc:creator>
      <dc:date>2022-06-14T13:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Questions about Indexing from a .csv file into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601746#M104830</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225099"&gt;@ramganeshn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;If this answer solves your need, please accept one answer for the other people of Community, or tell me hot I can help you more.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 14:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Questions-about-Indexing-from-a-csv-file-into-Splunk/m-p/601746#M104830</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-14T14:43:29Z</dc:date>
    </item>
  </channel>
</rss>

