<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extracting fields and values using csv in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503700#M85921</link>
    <description>&lt;P&gt;check&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lookup table files&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="breadcrumb"&gt;&lt;A href="http://localhost:8000/en-US/manager/TA-SplunkAnswers" target="_blank" rel="noopener"&gt;Settings&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;»&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://localhost:8000/en-US/manager/TA-SplunkAnswers/lookups" target="_blank" rel="noopener"&gt;Lookups&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;»&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Lookup table files&lt;BR /&gt;&lt;BR /&gt;For me, I create &lt;STRONG&gt;lookups&amp;nbsp;&lt;/STRONG&gt;folder in my apps ( /etc/apps/{myapps}/lookups/)&lt;BR /&gt;&amp;nbsp;and create lookup csv&lt;/DIV&gt;</description>
    <pubDate>Wed, 10 Jun 2020 09:06:45 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-06-10T09:06:45Z</dc:date>
    <item>
      <title>Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503682#M85915</link>
      <description>&lt;P&gt;Hi....I am relatively new to Splunk...&lt;/P&gt;
&lt;P&gt;So i am uploading a csv file as a input to splunk and trying to plot charts....The thing I have the contents of csv file in a specific format...&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="priyaramki16_0-1591774499708.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9079i9D9B8ED8C2855374/image-size/medium?v=v2&amp;amp;px=400" role="button" title="priyaramki16_0-1591774499708.png" alt="priyaramki16_0-1591774499708.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;so when i upload this csv to splunk it creates a table like this&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="priyaramki16_1-1591774982345.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9080iE11D56837A0C8197/image-size/medium?v=v2&amp;amp;px=400" role="button" title="priyaramki16_1-1591774982345.png" alt="priyaramki16_1-1591774982345.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The problem is the Names are not shown for certain rows (even though the user knows from seeing the csv that first 5 rows belong to Raja and next 5 rows belong to Pragya) and only in some rows Names can be seen..&lt;/P&gt;
&lt;P&gt;Is there anything we can do in splunk internally to solve this...Any help would be great!! Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 19:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503682#M85915</guid>
      <dc:creator>priyaramki16</dc:creator>
      <dc:date>2020-06-10T19:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503685#M85916</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="スクリーンショット 2020-06-10 16.58.20.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9081i6A98C950783149D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="スクリーンショット 2020-06-10 16.58.20.png" alt="スクリーンショット 2020-06-10 16.58.20.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I create CSV and search.&lt;BR /&gt;so your CSV is wrong, I guess.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 07:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503685#M85916</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-06-10T07:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503686#M85917</link>
      <description>&lt;P&gt;I used to display the content as table using this command in search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;table Name, Date, Icecream_purchased, Choco_purchased&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using as table can help in creating Charts&lt;/P&gt;&lt;P&gt;For chart creation:&lt;/P&gt;&lt;P&gt;|chart value(Icecream_purchased),value(Choco_purchased) over Name by Date&lt;BR /&gt;&lt;BR /&gt;Is there a way to get this chart if I use inputlookup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 08:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503686#M85917</guid>
      <dc:creator>priyaramki16</dc:creator>
      <dc:date>2020-06-10T08:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503687#M85918</link>
      <description>&lt;LI-CODE lang="markup"&gt;| inputlookup purchased.csv
| filldown Name
| xyseries Date Name Choco_purchased Icecream_purchased&lt;/LI-CODE&gt;&lt;P&gt;you don't need chart, I guess.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 08:14:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503687#M85918</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-06-10T08:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503690#M85919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In your CSV file all cell are not filled in "Name" column and due to that you can't see name populated in each row in splunk, you can use below query to achieve this.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup your_file.csv | filldown Name&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 10 Jun 2020 08:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503690#M85919</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-06-10T08:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503699#M85920</link>
      <description>&lt;P&gt;| inputlookup source_file_name.csv&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This search does not work for me...It gives me statistics(0) ...&lt;BR /&gt;Could there be any reason for this&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 08:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503699#M85920</guid>
      <dc:creator>priyaramki16</dc:creator>
      <dc:date>2020-06-10T08:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503700#M85921</link>
      <description>&lt;P&gt;check&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lookup table files&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="breadcrumb"&gt;&lt;A href="http://localhost:8000/en-US/manager/TA-SplunkAnswers" target="_blank" rel="noopener"&gt;Settings&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;»&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://localhost:8000/en-US/manager/TA-SplunkAnswers/lookups" target="_blank" rel="noopener"&gt;Lookups&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;»&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Lookup table files&lt;BR /&gt;&lt;BR /&gt;For me, I create &lt;STRONG&gt;lookups&amp;nbsp;&lt;/STRONG&gt;folder in my apps ( /etc/apps/{myapps}/lookups/)&lt;BR /&gt;&amp;nbsp;and create lookup csv&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Jun 2020 09:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503700#M85921</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-06-10T09:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503701#M85922</link>
      <description>&lt;P&gt;&lt;SPAN&gt;| inputlookup source_file_name.csv&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This search does not work for me...It gives me statistics(0) ...&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Could there be any reason for this&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 09:04:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503701#M85922</guid>
      <dc:creator>priyaramki16</dc:creator>
      <dc:date>2020-06-10T09:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields and values using csv in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503703#M85923</link>
      <description>&lt;P&gt;Thank you so much!! Got it&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 09:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Extracting-fields-and-values-using-csv-in-splunk/m-p/503703#M85923</guid>
      <dc:creator>priyaramki16</dc:creator>
      <dc:date>2020-06-10T09:11:08Z</dc:date>
    </item>
  </channel>
</rss>

