<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter columns from CSV while monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459074#M79297</link>
    <description>&lt;P&gt;Ok, I will try this&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2019 05:32:55 GMT</pubDate>
    <dc:creator>ankitarath2011</dc:creator>
    <dc:date>2019-08-23T05:32:55Z</dc:date>
    <item>
      <title>Filter columns from CSV while monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459072#M79295</link>
      <description>&lt;P&gt;I am monitoring a folder with csv files with 400+ fields, out of which need only 50 fields for my dashboard.&lt;BR /&gt;
Can we do something in Indexing time, so that it will not index the other 350 fields which are not required.&lt;/P&gt;

&lt;P&gt;Removing from CSV is not possible. So, need to handle it in splunk only.&lt;/P&gt;

&lt;P&gt;Please suggest.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 09:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459072#M79295</guid>
      <dc:creator>ankitarath2011</dc:creator>
      <dc:date>2019-08-22T09:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Filter columns from CSV while monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459073#M79296</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I don't know if it's working for 400+ fields but I found this post for you : &lt;A href="https://answers.splunk.com/answers/529138/filter-csv-logs-before-indexing.html"&gt;https://answers.splunk.com/answers/529138/filter-csv-logs-before-indexing.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 14:09:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459073#M79296</guid>
      <dc:creator>KailA</dc:creator>
      <dc:date>2019-08-22T14:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Filter columns from CSV while monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459074#M79297</link>
      <description>&lt;P&gt;Ok, I will try this&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 05:32:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459074#M79297</guid>
      <dc:creator>ankitarath2011</dc:creator>
      <dc:date>2019-08-23T05:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Filter columns from CSV while monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459075#M79298</link>
      <description>&lt;P&gt;Let me know if it works &lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 07:20:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459075#M79298</guid>
      <dc:creator>KailA</dc:creator>
      <dc:date>2019-08-23T07:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Filter columns from CSV while monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459076#M79299</link>
      <description>&lt;P&gt;You can do this with a carefully constructed &lt;CODE&gt;SEDCMD&lt;/CODE&gt; setting but this may not work if you are using &lt;CODE&gt;INDEXED_EXTRACTIONS=csv&lt;/CODE&gt; (then again, it may very well work).  I know that it definitely will work if you are not using &lt;CODE&gt;INDEXED_EXTRACTIONS&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 01:51:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-columns-from-CSV-while-monitoring/m-p/459076#M79299</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-09-02T01:51:35Z</dc:date>
    </item>
  </channel>
</rss>

