<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you properly upload CSV data to Splunk? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448999#M6188</link>
    <description>&lt;P&gt;I did do that and its very useful.&lt;/P&gt;

&lt;P&gt;But i was still trying to resolve my initial issue. Where my CSV files will not upload to Splunk.. it is frustrating&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 03:18:59 GMT</pubDate>
    <dc:creator>krhines410</dc:creator>
    <dc:date>2018-09-17T03:18:59Z</dc:date>
    <item>
      <title>How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448990#M6179</link>
      <description>&lt;P&gt;I am trying to be an admin for a separate work project. But our original admin has been out of town for a few weeks, so I am unable to ask him before my deadline. I was trying to get this sample project done..&lt;/P&gt;

&lt;P&gt;I have TXT file logs that I transfer over to Excel CSV sheets, and i use the first line as the field names, and the columns for each field have a flow of data. &lt;/P&gt;

&lt;P&gt;When I upload the the CSV to Splunk, all I am getting is a 100% bar but it is gray. When I upload the sample logs from Splunk, the bar goes green. &lt;/P&gt;

&lt;P&gt;Do you have any tips on making the data acceptable. My Excel sheet looks almost identical to Splunk's sample sheets but my data does not confirm with a green bar. &lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 04:22:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448990#M6179</guid>
      <dc:creator>krhines410</dc:creator>
      <dc:date>2018-09-05T04:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448991#M6180</link>
      <description>&lt;P&gt;Splunk Can Not index Excel files as those contain binary (propitiatory formatted) data.&lt;BR /&gt;
save your files as &lt;CODE&gt;.csv&lt;/CODE&gt; and enjoy Splunk power&lt;/P&gt;

&lt;P&gt;more related answers here:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/568971/what-is-the-best-way-to-index-excel-sheet-to-splun-1.html"&gt;https://answers.splunk.com/answers/568971/what-is-the-best-way-to-index-excel-sheet-to-splun-1.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/327256/when-indexing-an-excel-file-with-the-xlsx-file-ext.html"&gt;https://answers.splunk.com/answers/327256/when-indexing-an-excel-file-with-the-xlsx-file-ext.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 11:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448991#M6180</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-09-08T11:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448992#M6181</link>
      <description>&lt;P&gt;hi @krhines410,&lt;/P&gt;

&lt;P&gt;Did the answer below solve your problem? If so, please resolve this post by approving it! &lt;/P&gt;

&lt;P&gt;If your problem is still not solved, keep us updated so that someone else can help ya.&lt;/P&gt;

&lt;P&gt;Thanks for posting!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 18:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448992#M6181</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-11T18:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448993#M6182</link>
      <description>&lt;P&gt;Have you try the untable command?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Sep 2018 21:34:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448993#M6182</guid>
      <dc:creator>felipesewaybric</dc:creator>
      <dc:date>2018-09-16T21:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448994#M6183</link>
      <description>&lt;P&gt;Adonio has an excellent answer.  I would also recommend the lookup editor app on SplunkBase.  Lets you cut and paste from a spreadsheet with automatic insertion of new lines.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Sep 2018 22:15:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448994#M6183</guid>
      <dc:creator>MonkeyK</dc:creator>
      <dc:date>2018-09-16T22:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448995#M6184</link>
      <description>&lt;P&gt;Make sure that you do &lt;CODE&gt;Save As&lt;/CODE&gt; in &lt;CODE&gt;Excel&lt;/CODE&gt; and select &lt;CODE&gt;DOS CSV&lt;/CODE&gt; or &lt;CODE&gt;Windows CSV&lt;/CODE&gt; or even &lt;CODE&gt;plain text&lt;/CODE&gt;.  Then open the file with &lt;CODE&gt;Notepad++&lt;/CODE&gt; and make sure that it looks the way that it should.  Then upload this version if the file.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Sep 2018 23:59:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448995#M6184</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-09-16T23:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448996#M6185</link>
      <description>&lt;P&gt;First, &lt;STRONG&gt;save&lt;/STRONG&gt; as your excel file in &lt;STRONG&gt;CSV file&lt;/STRONG&gt; and then open it into &lt;STRONG&gt;notepad++&lt;/STRONG&gt; or any &lt;STRONG&gt;text editor&lt;/STRONG&gt; to verify it.  If your &lt;STRONG&gt;data&lt;/STRONG&gt; having a &lt;STRONG&gt;comma&lt;/STRONG&gt; as a value then make sure you need to select &lt;STRONG&gt;different separator&lt;/STRONG&gt; as csv data separator, like pipe. &lt;/P&gt;

&lt;P&gt;After creating proper csv file upload into splunk&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 02:04:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448996#M6185</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2018-09-17T02:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448997#M6186</link>
      <description>&lt;P&gt;&lt;A href="https://www.google.com/search?q=upload+csv+to+splunk&amp;amp;oq=upload+csv+to+spl&amp;amp;aqs=chrome.2.69i57j69i60j0l3.4807j0j7&amp;amp;client=ms-android-hms-tmobile-us&amp;amp;sourceid=chrome-mobile&amp;amp;ie=UTF-8"&gt;Blog post&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This blog post has good information!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 02:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448997#M6186</guid>
      <dc:creator>Noah_Woodcock</dc:creator>
      <dc:date>2018-09-17T02:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448998#M6187</link>
      <description>&lt;P&gt;I converted a txt document to an excel spreadsheet and saved it as .csv. inside excel.&lt;/P&gt;

&lt;P&gt;The downloaded test data that Splunk provides is Excel .csv &lt;/P&gt;

&lt;P&gt;When you upload my document the percentage bar will go to a 100% but it is grayed. &lt;/P&gt;

&lt;P&gt;When you upload Splunks excel sheet it goes 100% green.&lt;/P&gt;

&lt;P&gt;Is it due to the fact that they are in zipped csv files? &lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 03:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448998#M6187</guid>
      <dc:creator>krhines410</dc:creator>
      <dc:date>2018-09-17T03:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448999#M6188</link>
      <description>&lt;P&gt;I did do that and its very useful.&lt;/P&gt;

&lt;P&gt;But i was still trying to resolve my initial issue. Where my CSV files will not upload to Splunk.. it is frustrating&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 03:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/448999#M6188</guid>
      <dc:creator>krhines410</dc:creator>
      <dc:date>2018-09-17T03:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/449000#M6189</link>
      <description>&lt;P&gt;Was not aware that I should do Notepad++ going to be looking into that..&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 03:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/449000#M6189</guid>
      <dc:creator>krhines410</dc:creator>
      <dc:date>2018-09-17T03:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/449001#M6190</link>
      <description>&lt;P&gt;I have had problems with the way that &lt;CODE&gt;Notepad&lt;/CODE&gt; handles newlines on Windows for Splunk files.  I have never had any problems with &lt;CODE&gt;Notepad++&lt;/CODE&gt;.  I actually use &lt;CODE&gt;vi&lt;/CODE&gt; and &lt;CODE&gt;mobaxterm&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 22:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/449001#M6190</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-09-19T22:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do you properly upload CSV data to Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/449002#M6191</link>
      <description>&lt;P&gt;I think you have a problem with your links; I only see a google search, @noah_woodcock.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 22:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-you-properly-upload-CSV-data-to-Splunk/m-p/449002#M6191</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-09-19T22:27:52Z</dc:date>
    </item>
  </channel>
</rss>

