<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: error during csv index extraction in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251556#M48425</link>
    <description>&lt;P&gt;ok - what I was thinking but nice to get some confirmation. &lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2016 14:26:02 GMT</pubDate>
    <dc:creator>ebaileytu</dc:creator>
    <dc:date>2016-08-30T14:26:02Z</dc:date>
    <item>
      <title>error during csv index extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251554#M48423</link>
      <description>&lt;P&gt;I have setup a process where a heavy forwarder is ingesting a large number of csv files and the process seems to be working, but I am seeing the following error message for every single csv file&lt;/P&gt;

&lt;P&gt;08-26-2016 08:41:19.386 -0500 WARN  CsvLineBreaker - CSV StreamId: 2416848287927153596 has empty line. - data_source="/shared/storage_performance/storage/Hitachi/xxxxx/PhyLDEV_dat/xxxxx_8_26_2016_0746_PHY_Long_LDEV_1-7_0.csv", data_host="xxxxx", data_sourcetype="hitachi_perf"&lt;/P&gt;

&lt;P&gt;Any idea what this means? I do see a blank line at the end of each CSV file. The data is being extracted as desired and the only issue I see other than the error message is the process is not very fast.&lt;/P&gt;

&lt;P&gt;I am using 6.3.3&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;P&gt;[batch:///shared/storage_performance/storage/Hitachi]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
host_segment = 5&lt;BR /&gt;
index = storage&lt;BR /&gt;
sourcetype = hitachi_perf&lt;BR /&gt;
move_policy = sinkhole&lt;BR /&gt;
crcSalt     = &lt;BR /&gt;
recursive = true&lt;BR /&gt;
whitelist = .csv$&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;P&gt;[hitachi_perf]&lt;BR /&gt;
category = Custom&lt;BR /&gt;
description = Corp Hitachi Performance Data&lt;BR /&gt;
pulldown_type = 1&lt;BR /&gt;
DATETIME_CONFIG =&lt;BR /&gt;
INDEXED_EXTRACTIONS = csv&lt;BR /&gt;
KV_MODE = none&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
TZ = GMT&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251554#M48423</guid>
      <dc:creator>ebaileytu</dc:creator>
      <dc:date>2020-09-29T10:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: error during csv index extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251555#M48424</link>
      <description>&lt;P&gt;That error is merely telling you that it found a blank line within the CSV file. Notice it is just a WARN. It appears the file is still importing without issue. I think you can safely ignore these warnings.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 13:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251555#M48424</guid>
      <dc:creator>jpolcari</dc:creator>
      <dc:date>2016-08-30T13:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: error during csv index extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251556#M48425</link>
      <description>&lt;P&gt;ok - what I was thinking but nice to get some confirmation. &lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 14:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251556#M48425</guid>
      <dc:creator>ebaileytu</dc:creator>
      <dc:date>2016-08-30T14:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: error during csv index extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251557#M48426</link>
      <description>&lt;P&gt;Is it possible to suppress the error per-sourcetype so as not to clutter the logs?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 18:54:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/error-during-csv-index-extraction/m-p/251557#M48426</guid>
      <dc:creator>ATB_Jesse</dc:creator>
      <dc:date>2018-06-14T18:54:24Z</dc:date>
    </item>
  </channel>
</rss>

