<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputcsv returning no results in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71523#M14555</link>
    <description>&lt;P&gt;Glad you found the answer to the issue, I didn't think of that.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2013 13:17:19 GMT</pubDate>
    <dc:creator>chris</dc:creator>
    <dc:date>2013-06-24T13:17:19Z</dc:date>
    <item>
      <title>inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71519#M14551</link>
      <description>&lt;P&gt;All,&lt;/P&gt;

&lt;P&gt;I am trying to read a csv file using the inputcsv command.  I can't seem to figure out why, but the command isn't returning any results.  The file (call it names.csv) is a list of names, like so:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Users
Bob Smith
Joe Somebody
John Doe
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The file is located in var/run/splunk, as the documentation on inputcsv says it should.  When I run the command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|inputcsv names.csv
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I get no search results.  Clicking the "Inspect..." link provides the following details:&lt;/P&gt;

&lt;PRE&gt;This search has completed, but did not match any events. The terms specified in the highlighted portion of the search:&lt;PRE&gt;&lt;B&gt;None&lt;/B&gt; | inputcsv names.csv&lt;/PRE&gt;&lt;/PRE&gt;

&lt;P&gt;"None" is the highlighted portion of the search, which makes me believe that it is not correctly parsing the inputcsv command as it should.  I could, however, just be misinterpreting how the command should be used.&lt;/P&gt;

&lt;P&gt;Any help you could provide would be greatly appreciated.  Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 14:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71519#M14551</guid>
      <dc:creator>bruceclarke</dc:creator>
      <dc:date>2013-06-21T14:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71520#M14552</link>
      <description>&lt;P&gt;Hmm, this should work ... I just tried the same on an a Splunk instance i have acces to. I tried with different user roles admin,power,user all worked. Do you have a distributed environment (Seperate servers for search head &amp;amp; indexers)? Then you should create the file on the search head. Oh and by var/run/splunk you mean $SPLUNK_HOME/var/run/splunk right?  Oh and the  splunk process does have access to the file names.csv.  You're probably good an all those basic things, just trying to help you pin down the problem.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2013 11:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71520#M14552</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2013-06-23T11:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71521#M14553</link>
      <description>&lt;P&gt;Thanks for the comment.  I'm working on a distributed environment, but I do have the file on the search head.  I have the file in the correct location ($SPLUNK_HOME/var/run/splunk), and splunk should have access to it (I actually restricted access to it once and got an error message saying Splunk couldn't read the contents).&lt;/P&gt;

&lt;P&gt;I'm a little curious as to why the search highlights "None" which comes before the inputcsv command.  It almost seems to suggest that it's looking for something before the csv command, but not finding it.  Could you shed any light on that?&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2013 20:29:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71521#M14553</guid>
      <dc:creator>bruceclarke</dc:creator>
      <dc:date>2013-06-23T20:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71522#M14554</link>
      <description>&lt;P&gt;Ah, I figured it out.  The line endings were in Unix format, which must have been throwing the command off.  Once I switched them to Windows format, it worked.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2013 21:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71522#M14554</guid>
      <dc:creator>bruceclarke</dc:creator>
      <dc:date>2013-06-23T21:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71523#M14555</link>
      <description>&lt;P&gt;Glad you found the answer to the issue, I didn't think of that.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2013 13:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71523#M14555</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2013-06-24T13:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71524#M14556</link>
      <description>&lt;P&gt;I am stuck with similar issue. It throws error saying file could not be read. I created the file and placed it in specified directory splunk/var/run/splunk/csv/...&lt;BR /&gt;
I use command inputcsv filename.csv... &lt;BR /&gt;
File is not read and no results returned.&lt;BR /&gt;
Please help.&lt;/P&gt;

&lt;P&gt;File looks like this......&lt;BR /&gt;
InvApprover,Status&lt;BR /&gt;
pallavi ,approved&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 07:32:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71524#M14556</guid>
      <dc:creator>pallavibalasa</dc:creator>
      <dc:date>2016-08-29T07:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: inputcsv returning no results</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71525#M14557</link>
      <description>&lt;P&gt;@pallavibalasa - It looks like the accepted answer here does not apply to your problem. I was always able to see the file, which is not the case for you. I would suggest creating a new Splunk Answer post to address that, rather than commenting on a 3+ year old post that people might not see.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 13:21:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/inputcsv-returning-no-results/m-p/71525#M14557</guid>
      <dc:creator>bruceclarke</dc:creator>
      <dc:date>2016-08-29T13:21:51Z</dc:date>
    </item>
  </channel>
</rss>

