<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk handling csv file with each line have different format in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404590#M94770</link>
    <description>&lt;P&gt;Could you show us a few lines of example data?&lt;/P&gt;

&lt;P&gt;Although I'm pretty sure what you're trying to achieve will either be not possible or pretty complicated, but let's see. &lt;/P&gt;</description>
    <pubDate>Sat, 19 May 2018 22:13:47 GMT</pubDate>
    <dc:creator>xpac</dc:creator>
    <dc:date>2018-05-19T22:13:47Z</dc:date>
    <item>
      <title>splunk handling csv file with each line have different format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404589#M94769</link>
      <description>&lt;P&gt;dears,&lt;/P&gt;

&lt;P&gt;I have CSV file consist for example of multiple numbers of line each line has different header and length depending on word in the line for example if column two in file contains cpu then it will have header with 8 columns but if contain memory word it will have another header with 3 columns I had preprocessing script that was grepping file for word and create new file with correct header and set sourcetype in splunk as csv but this script is inefficient in large files so may i know if there is any solution direct from splunk that make me not use this script note number of different header is above 200 hundred &lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 21:16:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404589#M94769</guid>
      <dc:creator>ahmedhassanean</dc:creator>
      <dc:date>2018-05-19T21:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: splunk handling csv file with each line have different format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404590#M94770</link>
      <description>&lt;P&gt;Could you show us a few lines of example data?&lt;/P&gt;

&lt;P&gt;Although I'm pretty sure what you're trying to achieve will either be not possible or pretty complicated, but let's see. &lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 22:13:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404590#M94770</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-19T22:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk handling csv file with each line have different format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404591#M94771</link>
      <description>&lt;P&gt;for example log file will contain below &lt;BR /&gt;
coulmn1,cpu,coulmn2,coulmn3,coulmn4,coulmn5&lt;BR /&gt;
coulmn1,memory,coulmn2,coulmn3,coulmn4,coulmn5,coulmn6,coulmn7,coulmn8,coulmn9&lt;BR /&gt;
coulmn1,diskio,coulmn2,coulmn3&lt;/P&gt;

&lt;P&gt;header files contain below:&lt;BR /&gt;
for cpu header as below :&lt;BR /&gt;
metricx,metricz,metrixy,metric3,metric4,coulmn5&lt;/P&gt;

&lt;P&gt;for memroy header it will be as below : &lt;/P&gt;

&lt;P&gt;metric1metricx,metric2,metric3,metric4,metric5,metric6,metric7,metric8,metric9&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 22:18:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-handling-csv-file-with-each-line-have-different-format/m-p/404591#M94771</guid>
      <dc:creator>ahmedhassanean</dc:creator>
      <dc:date>2018-05-19T22:18:43Z</dc:date>
    </item>
  </channel>
</rss>

