<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to skip reading CVS heard from server where Splunk Universal Forwarder is installed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-skip-reading-CVS-heard-from-server-where-Splunk-Universal/m-p/496765#M84726</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;On server with Splunk Universal Forwarder installed we are monitoring cvs log  with a header and lines in the following format:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Status","Device Name","IP Address","Site","Last Backup Date"
"Success","Active Directory","10.123.456.78","Global","30-04-2020 20:11:05" 
"Failure","Active Directory","10.123.456.89","Global","30-04-2020 20:11:06" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk ingests "Header" line even with the following header related parameters in the props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[cvs_custom_sourcetype]
   DATETIME_CONFIG = CURRENT
   SHOULD_LINEMERGE = false
   LINE_BREAKER = ([\r\n]+)
   NO_BINARY_CHECK = true
   INDEXED_EXTRACTIONS = csv
   HEADER_FIELD_LINE_NUMBER = 1
   HEADER_FIELD_DELIMITER = ,
   HEADER_FIELD_QUOTE = "
   FIELD_QUOTE = "
   KV_MODE = none
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any suggestions why it is happening?&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2020 15:45:29 GMT</pubDate>
    <dc:creator>mlevsh</dc:creator>
    <dc:date>2020-05-13T15:45:29Z</dc:date>
    <item>
      <title>How to skip reading CVS heard from server where Splunk Universal Forwarder is installed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-skip-reading-CVS-heard-from-server-where-Splunk-Universal/m-p/496765#M84726</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;On server with Splunk Universal Forwarder installed we are monitoring cvs log  with a header and lines in the following format:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Status","Device Name","IP Address","Site","Last Backup Date"
"Success","Active Directory","10.123.456.78","Global","30-04-2020 20:11:05" 
"Failure","Active Directory","10.123.456.89","Global","30-04-2020 20:11:06" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk ingests "Header" line even with the following header related parameters in the props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[cvs_custom_sourcetype]
   DATETIME_CONFIG = CURRENT
   SHOULD_LINEMERGE = false
   LINE_BREAKER = ([\r\n]+)
   NO_BINARY_CHECK = true
   INDEXED_EXTRACTIONS = csv
   HEADER_FIELD_LINE_NUMBER = 1
   HEADER_FIELD_DELIMITER = ,
   HEADER_FIELD_QUOTE = "
   FIELD_QUOTE = "
   KV_MODE = none
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any suggestions why it is happening?&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 15:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-skip-reading-CVS-heard-from-server-where-Splunk-Universal/m-p/496765#M84726</guid>
      <dc:creator>mlevsh</dc:creator>
      <dc:date>2020-05-13T15:45:29Z</dc:date>
    </item>
  </channel>
</rss>

