<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to handle csv format at search level? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391079#M69932</link>
    <description>&lt;P&gt;Very kind @martin_mueller - thank you!&lt;/P&gt;</description>
    <pubDate>Mon, 12 Nov 2018 18:08:22 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2018-11-12T18:08:22Z</dc:date>
    <item>
      <title>Is there a way to handle csv format at search level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391077#M69930</link>
      <description>&lt;P&gt;Is there a way to handle &lt;CODE&gt;csv&lt;/CODE&gt; files without using &lt;CODE&gt;INDEXED_EXTRACTIONS = csv&lt;/CODE&gt; at all? As a rule of thumb, we defer field discovery to the search heads. So, is there a way to do it for the &lt;CODE&gt;csv&lt;/CODE&gt; format as well?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 15:59:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391077#M69930</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-11-12T15:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to handle csv format at search level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391078#M69931</link>
      <description>&lt;P&gt;Ignoring the obvious question (Why?), you can set up transforms.conf with &lt;CODE&gt;DELIMS&lt;/CODE&gt; and &lt;CODE&gt;FIELDS&lt;/CODE&gt; to parse &lt;CODE&gt;1,2,3&lt;/CODE&gt; into three named fields at search time on the indexers according to the search head's knowledge bundle.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 17:28:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391078#M69931</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-11-12T17:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to handle csv format at search level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391079#M69932</link>
      <description>&lt;P&gt;Very kind @martin_mueller - thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 18:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391079#M69932</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-11-12T18:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to handle csv format at search level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391080#M69933</link>
      <description>&lt;P&gt;And from our Sales Engineer - CSVs are nice because they’re so simple. There are commas delimiting fields and a field header. &lt;/P&gt;

&lt;P&gt;Example config - &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.0/Data/Extractfieldsfromfileswithstructureddata#Props.conf+"&gt;Extract fields from files with structured data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2018 18:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-handle-csv-format-at-search-level/m-p/391080#M69933</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-11-12T18:12:53Z</dc:date>
    </item>
  </channel>
</rss>

