<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSV file parsing issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683507#M114095</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254654"&gt;@phanikumarcs&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;probably Splunk doesn'r recognize the timestamp field and format you configured:&lt;/P&gt;&lt;P&gt;in your data I don't see the field "timestamp" with the format %Y-%m-%d %H:%M:%S, where is it?&lt;/P&gt;&lt;P&gt;Try to manualli add a sample of these data using the Add Data function that guides you in the sourcetype creation.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sun, 07 Apr 2024 04:56:55 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-04-07T04:56:55Z</dc:date>
    <item>
      <title>CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683503#M114094</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am parsing the CSV data to Splunk, testing in dev windows machine from UF.&lt;/P&gt;&lt;P&gt;This is the sample csv data:&lt;/P&gt;&lt;TABLE width="821"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="141"&gt;Subscription Name&lt;/TD&gt;&lt;TD width="168"&gt;&amp;nbsp;Resource Group Name&lt;/TD&gt;&lt;TD width="155"&gt;&amp;nbsp;Key Vault Name&lt;/TD&gt;&lt;TD width="195"&gt;&amp;nbsp;Secret Name&lt;/TD&gt;&lt;TD width="105"&gt;&amp;nbsp;Expiration Date&lt;/TD&gt;&lt;TD width="57"&gt;&amp;nbsp;Months&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SUB-dully&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto-cert&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;2022-07-28&lt;/TD&gt;&lt;TD&gt;-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SUB-gully&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto-cert&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;2022-07-28&lt;/TD&gt;&lt;TD&gt;-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SUB-pally&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;core-auto-cert&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;2022-09-01&lt;/TD&gt;&lt;TD&gt;-20&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output i am getting, all events in single event.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanikumarcs_0-1712457626978.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30288i4936A394641BADE7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanikumarcs_0-1712457626978.png" alt="phanikumarcs_0-1712457626978.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I created inputs.conf, sourcetype&lt;/P&gt;&lt;P&gt;where the sourcetype configurations are&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanikumarcs_1-1712457777865.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30289i751A257BE23A5440/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanikumarcs_1-1712457777865.png" alt="phanikumarcs_1-1712457777865.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can anyone help me why is it's not breaking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 02:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683503#M114094</guid>
      <dc:creator>phanikumarcs</dc:creator>
      <dc:date>2024-04-07T02:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683507#M114095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254654"&gt;@phanikumarcs&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;probably Splunk doesn'r recognize the timestamp field and format you configured:&lt;/P&gt;&lt;P&gt;in your data I don't see the field "timestamp" with the format %Y-%m-%d %H:%M:%S, where is it?&lt;/P&gt;&lt;P&gt;Try to manualli add a sample of these data using the Add Data function that guides you in the sourcetype creation.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 04:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683507#M114095</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-04-07T04:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683511#M114097</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;yeah i tried the data add via upload, there when i select sourcetype as csv there i can see the timestamp field.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 10:21:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683511#M114097</guid>
      <dc:creator>phanikumarcs</dc:creator>
      <dc:date>2024-04-07T10:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683512#M114098</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254654"&gt;@phanikumarcs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the timestamp field is one of the columns of your csv file or it's automatically generated by Splunk because it isn't present in the csv file?&lt;/P&gt;&lt;P&gt;I don't see the timestamp field in the screenshot you shared.&lt;/P&gt;&lt;P&gt;In your screenshot and in your table there are only the following fields:&amp;nbsp;Subscription Name, Resource Group Name, Key Vault Name, Secret Name, Expiration Date, Months.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 11:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683512#M114098</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-04-07T11:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683522#M114100</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Thanks for you help to understand the issue.&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Case1:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Actually, there is no timestamp present in the provided csv. In the snapshot you're seeing the data is getting from sample i ingested from the dev machine via UF, here even i am not able to see in the events no "timestamp" field.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanikumarcs_1-1712545093552.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30299i967200F0D7436DA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanikumarcs_1-1712545093552.png" alt="phanikumarcs_1-1712545093552.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Case2:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;When i upload the csv in the data inputs, after selecting the sourcetype as "cmkcsv" there it is showing the timestamp field. So here whatever settings i added in the advance it's not at all removing the warning flag as "failed to parse timestamp defaulting to file modtime"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phanikumarcs_0-1712544823949.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30298i39874BA51F9A9384/image-size/medium?v=v2&amp;amp;px=400" role="button" title="phanikumarcs_0-1712544823949.png" alt="phanikumarcs_0-1712544823949.png" /&gt;&lt;/span&gt;&lt;BR /&gt;[ cmkcsv ]&lt;BR /&gt;DATETIME_CONFIG=CURRENT&lt;BR /&gt;INDEXED_EXTRACTIONS=csv&lt;BR /&gt;KV_MODE=none&lt;BR /&gt;LINE_BREAKER=\n\W&lt;BR /&gt;NO_BINARY_CHECK=true&lt;BR /&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S&lt;BR /&gt;TRUNCATE=200&lt;BR /&gt;category=Structured&lt;BR /&gt;description=Comma-separated value format. Set header and other settings in "Delimited Settings"&lt;BR /&gt;disabled=false&lt;BR /&gt;pulldown_type=true&lt;BR /&gt;TIME_PREFIX=^\w+\s*\w+,\s*\w+,\s*&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD=20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 02:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683522#M114100</guid>
      <dc:creator>phanikumarcs</dc:creator>
      <dc:date>2024-04-08T02:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683554#M114104</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254654"&gt;@phanikumarcs&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as I supposed, Splunk dowsn't find the timestamp so it doesn't breaks the events.&lt;/P&gt;&lt;P&gt;Remove the timestamp option and maintain the linebreaker:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ cmkcsv ]
DATETIME_CONFIG=CURRENT
INDEXED_EXTRACTIONS=csv
KV_MODE=none
LINE_BREAKER=\r\n
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
TRUNCATE=200
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 05:45:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683554#M114104</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-04-08T05:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683605#M114107</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Yeah, understood and did the same thankyou.&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; any idea, need help here&lt;BR /&gt;So now i ingested the csv file, from this i am getting the&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;index=foo host=nx7503 source=C:/*/mkd.csv&lt;BR /&gt;Fields:&lt;BR /&gt;Subscription&lt;BR /&gt;Resource&lt;BR /&gt;Key Vault&lt;BR /&gt;Secret&lt;BR /&gt;Expiration Date&lt;BR /&gt;Months&lt;/P&gt;&lt;P&gt;CSV file:&lt;/P&gt;&lt;TABLE width="820"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="141"&gt;Subscription&lt;/TD&gt;&lt;TD width="168"&gt;&amp;nbsp;Resource&lt;/TD&gt;&lt;TD width="155"&gt;&amp;nbsp;Key Vault&lt;/TD&gt;&lt;TD width="195"&gt;&amp;nbsp;Secret&lt;/TD&gt;&lt;TD width="104"&gt;&amp;nbsp;Expiration Date&lt;/TD&gt;&lt;TD width="57"&gt;&amp;nbsp;Months&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;BoB-foo&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;Dicore-automat&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;Dicore-automat-keycore&lt;/TD&gt;&lt;TD&gt;Di&amp;nbsp;core-tuubsp1sct&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;2022-07-28&lt;/TD&gt;&lt;TD&gt;-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;BoB-foo&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;Dicore-automat&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;Dicore-automat-keycore&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;Dicore-stor1scrt&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;2022-07-28&lt;/TD&gt;&lt;TD&gt;-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;BoB-foo&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;G01462-mgmt-foo&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;G86413-vaultcore&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;G86413-secret-foo&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;2022-09-01&lt;/TD&gt;&lt;TD&gt;-20&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;And from the lookup(foo.csv)&lt;/P&gt;&lt;P&gt;Lookup: foo.csv&lt;/P&gt;&lt;TABLE width="892"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Application&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;environment&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;appOwner&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Caliber&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;Dicore - TCG&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;foo@gmail.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Keygroup&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;G01462 - QA&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;goo@gmail.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Keygroup&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;G01462 - SIT&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;boo@gmail.com&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when the "Expiration Date" match the "Resource" and "environment" trigger the alert and send mail to the respective emails(appOwner), how to get this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 15:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683605#M114107</guid>
      <dc:creator>phanikumarcs</dc:creator>
      <dc:date>2024-04-08T15:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683616#M114108</link>
      <description>&lt;P&gt;I am not sure what you are asking of me here - your original issue seems to have been solved by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 15:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683616#M114108</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-08T15:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683785#M114138</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; yes that is resolved. No worries.&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; please help&lt;/P&gt;&lt;P&gt;This is the other issue which is related to csv dataset and lookup dataset.&lt;BR /&gt;&lt;BR /&gt;From this SPL: &lt;STRONG&gt;source="cmkcsv.csv" host="DESKTOP" index="cmk" sourcetype="cmkcsv"&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Getting output below&lt;/P&gt;&lt;TABLE width="820"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="128px"&gt;Subscription&lt;/TD&gt;&lt;TD width="176px"&gt;&amp;nbsp;Resource&lt;/TD&gt;&lt;TD width="158px"&gt;&amp;nbsp;Key Vault&lt;/TD&gt;&lt;TD width="185px"&gt;&amp;nbsp;Secret&lt;/TD&gt;&lt;TD width="103px"&gt;&amp;nbsp;Expiration Date&lt;/TD&gt;&lt;TD width="69px"&gt;&amp;nbsp;Months&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="128px"&gt;BoB-foo&lt;/TD&gt;&lt;TD width="176px"&gt;&amp;nbsp;Dicore-automat&lt;/TD&gt;&lt;TD width="158px"&gt;&amp;nbsp;Dicore-automat-keycore&lt;/TD&gt;&lt;TD width="185px"&gt;Di&amp;nbsp;core-tuubsp1sct&lt;/TD&gt;&lt;TD width="103px"&gt;&amp;nbsp;2022-07-28&lt;/TD&gt;&lt;TD width="69px"&gt;-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="128px"&gt;BoB-foo&lt;/TD&gt;&lt;TD width="176px"&gt;&amp;nbsp;Dicore-automat&lt;/TD&gt;&lt;TD width="158px"&gt;&amp;nbsp;Dicore-automat-keycore&lt;/TD&gt;&lt;TD width="185px"&gt;&amp;nbsp;Dicore-stor1scrt&lt;/TD&gt;&lt;TD width="103px"&gt;&amp;nbsp;2022-07-28&lt;/TD&gt;&lt;TD width="69px"&gt;-21&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="128px"&gt;BoB-foo&lt;/TD&gt;&lt;TD width="176px"&gt;&amp;nbsp;G01462-mgmt-foo&lt;/TD&gt;&lt;TD width="158px"&gt;&amp;nbsp;G86413-vaultcore&lt;/TD&gt;&lt;TD width="185px"&gt;&amp;nbsp;G86413-secret-foo&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From this lookup: &lt;STRONG&gt;| inputlookup cmklookup.csv&lt;BR /&gt;&lt;/STRONG&gt;Getting output below&lt;/P&gt;&lt;TABLE width="892"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Application&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;environment&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;appOwner&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Caliber&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;Dicore - TCG&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;foo@gmail.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Keygroup&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;G01462 - QA&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;goo@gmail.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="241.771px" height="24px"&gt;Keygroup&lt;/TD&gt;&lt;TD width="256.76px" height="24px"&gt;G01462 - SIT&lt;/TD&gt;&lt;TD width="392.802px" height="24px"&gt;boo@gmail.com&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Combine the two queries into one, where the output will only display results where the 'environment' and 'Resource' fields match. For instance, if 'G01462' matches in both fields across both datasets, it should be included in the output. How i can do this, could anyone help here to write spl. I wrote some of the Spls but it's not working for me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;source="cmkcsv.csv" host="DESKTOP" index="cmk" sourcetype="cmkcsv"&lt;BR /&gt;|join type=inner [ | inputlookup cmklookup.csv environment]&lt;BR /&gt;&lt;BR /&gt;source="cmkcsv.csv" host="DESKTOP" index="cmk" sourcetype="cmkcsv"&lt;BR /&gt;| lookup cmklookup.csv environment AS "Resource" OUTPUT "environment"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 07:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683785#M114138</guid>
      <dc:creator>phanikumarcs</dc:creator>
      <dc:date>2024-04-10T07:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683791#M114140</link>
      <description>&lt;P&gt;If it is a new / different issue, please raise it as a new question, that way the solved one can stay solved and people can look to help with the unsolved one.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 07:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683791#M114140</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-10T07:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683793#M114142</link>
      <description>&lt;P&gt;Done thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 08:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683793#M114142</guid>
      <dc:creator>phanikumarcs</dc:creator>
      <dc:date>2024-04-10T08:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683801#M114147</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254654"&gt;@phanikumarcs&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 09:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-parsing-issue/m-p/683801#M114147</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-04-10T09:07:55Z</dc:date>
    </item>
  </channel>
</rss>

