<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index csv files with grouped fields? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513885#M87124</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm using Universal forwarder and trying to consume a complex csv file. Usually this works OK by configuring props.conf correctly on the forwarder. However, this CSV file is quite complex, with many Grouped Field. "{ }" to be used&amp;nbsp;for encapsulating outer most&amp;nbsp;list and "[]" for internal lists.&lt;BR /&gt;Every internal list within {} or []&amp;nbsp;will be comma separated.&lt;BR /&gt;&lt;BR /&gt;Is this possible to achieve? I mean to get the naming of the header fields correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since the header fields will change depending on which groups or lists have data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a good documentation of the csv file format, but haven't found any ways to make props.conf handle these grouped fields and lists.....&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2020 11:59:43 GMT</pubDate>
    <dc:creator>kjell_ml</dc:creator>
    <dc:date>2020-08-13T11:59:43Z</dc:date>
    <item>
      <title>Index csv files with grouped fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513885#M87124</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm using Universal forwarder and trying to consume a complex csv file. Usually this works OK by configuring props.conf correctly on the forwarder. However, this CSV file is quite complex, with many Grouped Field. "{ }" to be used&amp;nbsp;for encapsulating outer most&amp;nbsp;list and "[]" for internal lists.&lt;BR /&gt;Every internal list within {} or []&amp;nbsp;will be comma separated.&lt;BR /&gt;&lt;BR /&gt;Is this possible to achieve? I mean to get the naming of the header fields correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since the header fields will change depending on which groups or lists have data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a good documentation of the csv file format, but haven't found any ways to make props.conf handle these grouped fields and lists.....&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 11:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513885#M87124</guid>
      <dc:creator>kjell_ml</dc:creator>
      <dc:date>2020-08-13T11:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Index csv files with grouped fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513911#M87126</link>
      <description>Example data would be helpful, but I suspect the file is more complex than Splunk can handle. Splunk expects all CSV rows to have the same set of fields.&lt;BR /&gt;Consider creating a scripted input to ingest that file.</description>
      <pubDate>Thu, 13 Aug 2020 13:21:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513911#M87126</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-13T13:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Index csv files with grouped fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513915#M87127</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's an example, I have anonymized the data and broken it up on separate lines where the internal groups and lists occur: (Inside the [] brackets there can be data or not, depending on type of transactions. This is what messes up the header_field naming)&lt;/P&gt;&lt;P&gt;0-0-9-1,64,xxx.xxx.x.x,28fa2342-5b1b-4605-b178-f2ec2b0b5327,20200813151737.417061,ff-14f-3fffffff-00152,,,&lt;BR /&gt;{REGISTER,,3600,0,&lt;BR /&gt;[sip:+4700000000@xxx.xxxxxx.xxxxxx.xxx.xxxxxxxxxxx.xxx],&lt;BR /&gt;[sip:+4700000000@xxx.xxxxx.xxxxxx.xxx.xxxxxxxxxxx.xxx,tel:+4700000000],&lt;BR /&gt;sip:+4700000000@xxx.xxxxxx.xxxxxx.xxx.xxxxxxxxxxx.xxx,&lt;BR /&gt;[],&lt;BR /&gt;20200813151737.417083,417,20200813151742.479075,479,,0,-1,xxxx-x-xxxxx-xxx;xxxxx-xxxx-xx-xxxx=xxxxxxxxxxxxxxxx,0,xxxxxxx.xxx,,0,&lt;BR /&gt;[],&lt;BR /&gt;,&lt;BR /&gt;[&lt;BR /&gt;[255.671.3043243843-1293344657.140,Ioi1,12345,]&lt;BR /&gt;]},&lt;BR /&gt;{[0,0,,0,0,0,0,xxxx-x-xxxxx-xxx,0],&lt;BR /&gt;},&lt;BR /&gt;{1,0,,0,0,0,false},&lt;BR /&gt;,,,,,,,,,,,,,&lt;BR /&gt;{[3,2,20200813151737.419758,REGISTER,0,xx.xx.x.xx,xxx.xxx.x.xx],&lt;BR /&gt;[3,2,20200813151742.434086,REGISTER,0,xxx.xxx.xx.xxx,xxx.xxx.xx.xxx],&lt;BR /&gt;[3,2,20200813151742.467122,200,0,xxx.xxx.xx.xxx,xxx.xxx.xx.xxx],&lt;BR /&gt;[3,2,20200813151742.478905,200,0,xxx.xxx.xx.xxx,xx.xx.x.xx]}\x00&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 13:36:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-csv-files-with-grouped-fields/m-p/513915#M87127</guid>
      <dc:creator>kjell_ml</dc:creator>
      <dc:date>2020-08-13T13:36:36Z</dc:date>
    </item>
  </channel>
</rss>

