<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is field ingestion not working when ingesting custom CSV data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412319#M72985</link>
    <description>&lt;P&gt;the first line of the csv file is the CIM field names that correspond to the data. I don't think that I am using indexed_extractions=csv. &lt;/P&gt;</description>
    <pubDate>Sun, 21 Apr 2019 16:37:07 GMT</pubDate>
    <dc:creator>grantccarlson</dc:creator>
    <dc:date>2019-04-21T16:37:07Z</dc:date>
    <item>
      <title>Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412312#M72978</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I am trying to ingest some custom CSV data that I have created. In some of the data it extracts the correct fields, but then also shows duplicate fields as "field 1", "field 2", etc. &lt;/P&gt;

&lt;P&gt;Any ideas how to have the data ingest correctly? Attached is a screenshot.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6890i9C87FFBF8B7A02F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I have tried creating field aliases and rules when ingesting but I am not having any luck. &lt;/P&gt;

&lt;P&gt;Thank you in advance for any help! &lt;/P&gt;</description>
      <pubDate>Sat, 20 Apr 2019 18:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412312#M72978</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-20T18:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412313#M72979</link>
      <description>&lt;P&gt;What are the props.conf and transforms.conf settings for the sourcetype?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 03:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412313#M72979</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-04-21T03:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412314#M72980</link>
      <description>&lt;P&gt;I'm not sure. How do you check? &lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 03:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412314#M72980</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-21T03:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412315#M72981</link>
      <description>&lt;P&gt;You read the .conf files or use btool.  Since you asked, however, I'll assume you did not change them.&lt;BR /&gt;
How did you ingest the CSV file?  Did you use the Add Data wizard?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 12:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412315#M72981</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-04-21T12:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412316#M72982</link>
      <description>&lt;P&gt;Your screenshot and your description do not match.  There are no duplicated fields shown.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 15:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412316#M72982</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-21T15:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412317#M72983</link>
      <description>&lt;P&gt;"Field 6" is the same as "dport" &lt;BR /&gt;
"field 4" is the same as "daddr"&lt;BR /&gt;
"event_code" is the same as "saddr" &lt;/P&gt;

&lt;P&gt;All of the above are the same field values with 2 different names...Sorry! Duplicate fields is probably not the best wording. &lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 15:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412317#M72983</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-21T15:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412318#M72984</link>
      <description>&lt;P&gt;What is the first line of the csv file and how are you getting it in?  Are you using &lt;CODE&gt;INDEXED_EXTRACTIONS=csv&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 15:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412318#M72984</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-04-21T15:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412319#M72985</link>
      <description>&lt;P&gt;the first line of the csv file is the CIM field names that correspond to the data. I don't think that I am using indexed_extractions=csv. &lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2019 16:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412319#M72985</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-21T16:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412320#M72986</link>
      <description>&lt;P&gt;@grantccarlson you would need to share your props.conf and transforms.conf applicable for this sourcetype. Would it be possible for you to do so?&lt;/P&gt;

&lt;P&gt;Also if possible share sample data file with CSV Header row  and at-least one data row. Kindly mock/anonymize any sensitive information before sharing data/code.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 03:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412320#M72986</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-04-22T03:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412321#M72987</link>
      <description>&lt;P&gt;Hello, I'm not sure where to find the props.conf and transforms.conf files. I will attach a screenshot to show the data file. &lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 14:55:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412321#M72987</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-22T14:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412322#M72988</link>
      <description>&lt;P&gt;"Timestamp  proto   saddr   daddr   sport   dport   spkts   dpkts   sbytes  dbytes  stcpb   State&lt;BR /&gt;
1473729384  tcp 94.255.165.163  140.226.22.228  23237   23  1   0   64  0   2363627212  REQ&lt;BR /&gt;
1473729384  tcp 36.69.63.66 164.47.8.18 43092   2323    1   0   64  0   2754545844  REQ&lt;BR /&gt;
1473729384  tcp 41.174.140.215  161.98.74.245   48716   2323    1   0   64  0   2707573431  REQ&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 14:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412322#M72988</guid>
      <dc:creator>grantccarlson</dc:creator>
      <dc:date>2019-04-22T14:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is field ingestion not working when ingesting custom CSV data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412323#M72989</link>
      <description>&lt;P&gt;It looks like you set up a field extraction without editing the field names and then saved it. &lt;/P&gt;

&lt;P&gt;To remove them, you will need to remove the field extraction. Go to Settings-&amp;gt;Fields-&amp;gt;Field Extractions. Make sure you have the right app selected. Filter by the name of your sourcetype. If you don't know that, sort by owner and look for your username. Delete the entry that you did not mean to create. &lt;/P&gt;

&lt;P&gt;If you see multiple entries and are unsure which one is yours go to Settings-&amp;gt;Fields-&amp;gt;Field Transoformations. Sort by owner and click into the ones owned by your username. Look for the one that has a field list similar to the one below:&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6889iE49A92243F1AA47F/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;
Take note of the name on that screen at the upper left hand corner. Go back to Settings-&amp;gt;Fields-&amp;gt;Field Extractions. Find the extraction that has your name as owner with that transformation name in its name. Delete it. &lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 16:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-field-ingestion-not-working-when-ingesting-custom-CSV/m-p/412323#M72989</guid>
      <dc:creator>behudelson</dc:creator>
      <dc:date>2019-04-22T16:18:36Z</dc:date>
    </item>
  </channel>
</rss>

