<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSV file with column named &amp;quot;Index&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261251#M50132</link>
    <description>&lt;P&gt;I've got a CSV file with a column called "Index." Naturally, this is a bit of a problem. Is there a way to deal with this other than making a new sourcetype for it and specifying the header row? I'd rather not do that because:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I actually have about 5 related CSV types with the same issue,&lt;/LI&gt;
&lt;LI&gt;The exact column headers may change subtly between different software loads on the devices uploading them, and&lt;/LI&gt;
&lt;LI&gt;I'm lazy, and this is something I'd only use occasionally. It might be easier for me to just hand-edit or sed the input files to rename the field.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I see a field called extracted_index when these files come in, and it appears to have the original value in it, but I can't seem to use it in a search or eval or stats command like I want to. What's up with that?&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2016 14:35:32 GMT</pubDate>
    <dc:creator>apnetmedic</dc:creator>
    <dc:date>2016-03-24T14:35:32Z</dc:date>
    <item>
      <title>CSV file with column named "Index"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261251#M50132</link>
      <description>&lt;P&gt;I've got a CSV file with a column called "Index." Naturally, this is a bit of a problem. Is there a way to deal with this other than making a new sourcetype for it and specifying the header row? I'd rather not do that because:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I actually have about 5 related CSV types with the same issue,&lt;/LI&gt;
&lt;LI&gt;The exact column headers may change subtly between different software loads on the devices uploading them, and&lt;/LI&gt;
&lt;LI&gt;I'm lazy, and this is something I'd only use occasionally. It might be easier for me to just hand-edit or sed the input files to rename the field.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I see a field called extracted_index when these files come in, and it appears to have the original value in it, but I can't seem to use it in a search or eval or stats command like I want to. What's up with that?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 14:35:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261251#M50132</guid>
      <dc:creator>apnetmedic</dc:creator>
      <dc:date>2016-03-24T14:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file with column named "Index"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261252#M50133</link>
      <description>&lt;P&gt;I am skeptical of your assertion at the end.  You definitely should be able use &lt;CODE&gt;extracted_index&lt;/CODE&gt; (or &lt;CODE&gt;extracted_Index&lt;/CODE&gt;?)  That's the whole reason that Splunk creates it!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 15:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261252#M50133</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-03-24T15:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: CSV file with column named "Index"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261253#M50134</link>
      <description>&lt;P&gt;Ah! Indeed. Victim of my own typo. I had "index" on the brain and thus typed it as such: extracted_index, lowercase. Original field was Index, so it's extracted_Index.&lt;/P&gt;

&lt;P&gt;All is right with the world.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:12:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CSV-file-with-column-named-quot-Index-quot/m-p/261253#M50134</guid>
      <dc:creator>apnetmedic</dc:creator>
      <dc:date>2020-09-29T09:12:10Z</dc:date>
    </item>
  </channel>
</rss>

