<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PROPS Conf with Header in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564363#M196606</link>
    <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;.....I am sending same thing again as some issues&amp;nbsp; .....sending text&amp;nbsp; with Red and Green color codes.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But, using your code ...getting some errors&amp;nbsp;&lt;STRONG&gt;"Failed to parse timestamp",&lt;/STRONG&gt;&amp;nbsp; fields/headers are not mapping to correct values&amp;nbsp;&amp;nbsp;and just to let you know source FILE is not&amp;nbsp;&lt;STRONG&gt;csv&lt;/STRONG&gt;&amp;nbsp;it's&amp;nbsp;&lt;STRONG&gt;Text&lt;/STRONG&gt;&amp;nbsp;file. Thank you again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;am giving the events again ......&lt;STRONG&gt;UserID and Timestamp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;values are marked as &lt;STRONG&gt;Bold&lt;/STRONG&gt; Below&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;STRONG&gt;UserId&lt;/STRONG&gt;&lt;SPAN&gt;, UserType, System, EventType, EventId, STF, SessionId, SourceAddress, RCode, ErrorMsg,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Timestamp&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, Dataload, Period, WFftCode, ReturnType, DataType&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;&lt;STRONG&gt;2021-08-19 08:05:52,763-CDT - FETCE&lt;/STRONG&gt;,SRGEE&lt;/SPAN&gt;,SAATCA,FETCHFA,&lt;SPAN&gt;FI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,&lt;STRONG&gt;20210819130552&lt;/STRONG&gt;,UCJ3R8,,,1,0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;&lt;STRONG&gt;2021-08-19 08:06:53,564-CDT - FETCE&lt;/STRONG&gt;,SRGEE&lt;/SPAN&gt;,SAATCA,FA,FETCHFI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,&lt;STRONG&gt;&lt;SPAN&gt;20210819130653&lt;/SPAN&gt;&lt;/STRONG&gt;,UCJ3R8,,,1,0&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-content-wrapper"&gt;&lt;DIV class="lia-panel-content"&gt;&lt;DIV class="AddMessageTags lia-message-tags"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 23 Aug 2021 14:55:08 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2021-08-23T14:55:08Z</dc:date>
    <item>
      <title>PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564248#M196552</link>
      <description>&lt;P&gt;Hello, I have some issues to create PROPS Conf file for following sample data events. It's a text file with header in it. I created one, but not working. Thank you so much, any help will be highly appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sample Events&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;UserId, UserType, System, EventType, EventId, STF, SessionId, SourceAddress, RCode, ErrorMsg, Timestamp, Dataload, Period, WFftCode, ReturnType, DataType&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;2021-08-19 08:05:52,763-CDT - SFTCE,IDCSEE,SATA,FA,FETCHFI,000000000,E3CE4819360E57124D220634E0D,sata,00,Successful,20210819130552,SCM3R8,,,1,0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;2021-08-19 08:06:53,564-CDT - SFTCE,IDCSEE,SATA,FA,FETCHFI,000000000,E3CE4819360E57124D220634E0D,sata,00,Successful,20210819130653,SCM3R8,,,1,0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;STRONG&gt;What I wrote my PROPS Conf file&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;[ __auto__learned__ ]&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;SHOULD_LINEMERGE=false&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;LINE_BREAKER=([\r\n]+)&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;INDEXED_EXTRACTIONS=psv&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S .%3N&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIMESTAMP_FIELDS=TIMESTAMP&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 02:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564248#M196552</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-23T02:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564253#M196557</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp; Deploy props to Universal forwarder&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source_type_name]
INDEXED_EXTRACTIONS=csv
TIME_FORMAT=%Y-%m-%d %H:%M:%S,%3Q
TIMESTAMP_FIELDS=Timestamp
HEADER_FIELD_LINE_NUMBER = 1&lt;/LI-CODE&gt;&lt;P&gt;Hope it helps!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 04:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564253#M196557</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-23T04:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564328#M196589</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much, appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, using your code ...getting some errors &lt;STRONG&gt;"Failed to parse timestamp"&lt;/STRONG&gt;&amp;nbsp; and&amp;nbsp; getting values &lt;STRONG&gt;UserId&lt;/STRONG&gt;=&lt;SPAN&gt;2021-08-19 08:05:52,763,......&amp;nbsp;&lt;STRONG&gt;System&lt;/STRONG&gt;=SATA.....so on and source FILE is not &lt;STRONG&gt;csv&lt;/STRONG&gt; it's &lt;STRONG&gt;Text&lt;/STRONG&gt; file. Thank you again.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 13:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564328#M196589</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-23T13:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564359#M196603</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you so much, appreciated.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But, using your code ...getting some errors&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;"Failed to parse timestamp",&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp; fields/headers are not mapping to correct values&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;and just to let you know source FILE is not&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;csv&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;it's&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;Text&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;file. Thank you again.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I&lt;/STRONG&gt; am giving the events again ......&lt;STRONG&gt;UserID and Timestamp &lt;/STRONG&gt;values are marked as&amp;nbsp;&lt;SPAN&gt;RED &lt;/SPAN&gt;&lt;SPAN&gt;and&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;Green&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;respectively,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;UserId&lt;/SPAN&gt;&lt;SPAN&gt;, UserType, System, EventType, EventId, STF, SessionId, SourceAddress, RCode, ErrorMsg, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Timestamp&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, Dataload, Period, WFftCode, ReturnType, DataType&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;2021-08-19 08:05:52,763-CDT - FETCE,SRGEE&lt;/SPAN&gt;,SAATCA,FETCHFA,&lt;SPAN&gt;FI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,&lt;STRONG&gt;&lt;SPAN&gt;20210819130552&lt;/SPAN&gt;&lt;/STRONG&gt;,UCJ3R8,,,1,0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;2021-08-19 08:06:53,564-CDT - FETCE,SRGEE&lt;/SPAN&gt;,SAATCA,FA,FETCHFI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,&lt;STRONG&gt;&lt;SPAN&gt;20210819130653&lt;/SPAN&gt;&lt;/STRONG&gt;,UCJ3R8,,,1,0&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 14:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564359#M196603</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-23T14:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564363#M196606</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;.....I am sending same thing again as some issues&amp;nbsp; .....sending text&amp;nbsp; with Red and Green color codes.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But, using your code ...getting some errors&amp;nbsp;&lt;STRONG&gt;"Failed to parse timestamp",&lt;/STRONG&gt;&amp;nbsp; fields/headers are not mapping to correct values&amp;nbsp;&amp;nbsp;and just to let you know source FILE is not&amp;nbsp;&lt;STRONG&gt;csv&lt;/STRONG&gt;&amp;nbsp;it's&amp;nbsp;&lt;STRONG&gt;Text&lt;/STRONG&gt;&amp;nbsp;file. Thank you again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;am giving the events again ......&lt;STRONG&gt;UserID and Timestamp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;values are marked as &lt;STRONG&gt;Bold&lt;/STRONG&gt; Below&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;STRONG&gt;UserId&lt;/STRONG&gt;&lt;SPAN&gt;, UserType, System, EventType, EventId, STF, SessionId, SourceAddress, RCode, ErrorMsg,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Timestamp&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, Dataload, Period, WFftCode, ReturnType, DataType&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;&lt;STRONG&gt;2021-08-19 08:05:52,763-CDT - FETCE&lt;/STRONG&gt;,SRGEE&lt;/SPAN&gt;,SAATCA,FETCHFA,&lt;SPAN&gt;FI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,&lt;STRONG&gt;20210819130552&lt;/STRONG&gt;,UCJ3R8,,,1,0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="xmsonormal"&gt;&lt;SPAN&gt;&lt;STRONG&gt;2021-08-19 08:06:53,564-CDT - FETCE&lt;/STRONG&gt;,SRGEE&lt;/SPAN&gt;,SAATCA,FA,FETCHFI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,&lt;STRONG&gt;&lt;SPAN&gt;20210819130653&lt;/SPAN&gt;&lt;/STRONG&gt;,UCJ3R8,,,1,0&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&lt;DIV class="lia-decoration-border"&gt;&lt;DIV class="lia-decoration-border-top"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-decoration-border-content"&gt;&lt;DIV&gt;&lt;DIV class="lia-panel-content-wrapper"&gt;&lt;DIV class="lia-panel-content"&gt;&lt;DIV class="AddMessageTags lia-message-tags"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Aug 2021 14:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564363#M196606</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-23T14:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564691#M196703</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;your content might be .txt however it is having header with comma's perfect structured except&amp;nbsp; a simple issue with data that has prevented parsing see below the very first UserId field having no double quotes around..(inherently having comma ,763). I have changed the contents as below for testing...to map to correct fields which seems working fine.&lt;/P&gt;&lt;P&gt;Having double quotes around works fine. If you have control over source change that otherwise you can not do much at forwarding layer... you have to process them at indexing layer or during search-time.&lt;/P&gt;&lt;P&gt;UserId, UserType, System, EventType, EventId, STF, SessionId, SourceAddress, RCode, ErrorMsg, Timestamp, Dataload, Period, WFftCode, ReturnType, DataType&lt;BR /&gt;&lt;STRONG&gt;"2021-08-19 08:05:52,763-CDT - FETCE"&lt;/STRONG&gt;,SRGEE,SAATCA,FETCHFA,FI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,20210819130552,UCJ3R8,,,1,0&lt;BR /&gt;&lt;STRONG&gt;"2021-08-19 08:06:53,564-CDT - FETCE"&lt;/STRONG&gt;,SRGEE,SAATCA,FA,FETCHFI,000000000,E3CE4819360E57124D220634E0D,saatca,00,Successful,20210819130653,UCJ3R8,,,1,0&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venkatasri_0-1629893662930.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15723iA42536E03E0DE8FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venkatasri_0-1629893662930.png" alt="venkatasri_0-1629893662930.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ __auto__learned__ ]
INDEXED_EXTRACTIONS=csv
HEADERFIELD_LINE_NUMBER=1
TIMESTAMP_FIELDS=Timestamp
TIME_FORMAT=%Y%m%d%H%M%S&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 12:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564691#M196703</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-25T12:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS Conf with Header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564696#M196706</link>
      <description>&lt;P&gt;Make sense, thank you appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 12:45:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-Conf-with-Header/m-p/564696#M196706</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-25T12:45:25Z</dc:date>
    </item>
  </channel>
</rss>

