<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field Extraction do not work when using the UPLOAD method in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17062#M2332</link>
    <description>&lt;P&gt;Customer's issue was actually that for csv files, when setting the CHECK_FOR_HEADER=TRUE in props.conf and when uploading the file using the one time upload button through splunkweb, no automatic field extraction would happen.&lt;/P&gt;

&lt;P&gt;I was able to reproduce this in my environment but the issue seems to go even further.
When using props.conf to extract fields (at index time, this is no longer a csv-header issue) and then uploading a file, no field extractions happen at all.&lt;/P&gt;

&lt;P&gt;Is this the default behavior? Is there any documentation about it?&lt;BR /&gt;
Is it a bug?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2010 01:21:01 GMT</pubDate>
    <dc:creator>Genti</dc:creator>
    <dc:date>2010-07-09T01:21:01Z</dc:date>
    <item>
      <title>Field Extraction do not work when using the UPLOAD method</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17062#M2332</link>
      <description>&lt;P&gt;Customer's issue was actually that for csv files, when setting the CHECK_FOR_HEADER=TRUE in props.conf and when uploading the file using the one time upload button through splunkweb, no automatic field extraction would happen.&lt;/P&gt;

&lt;P&gt;I was able to reproduce this in my environment but the issue seems to go even further.
When using props.conf to extract fields (at index time, this is no longer a csv-header issue) and then uploading a file, no field extractions happen at all.&lt;/P&gt;

&lt;P&gt;Is this the default behavior? Is there any documentation about it?&lt;BR /&gt;
Is it a bug?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2010 01:21:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17062#M2332</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-07-09T01:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction do not work when using the UPLOAD method</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17063#M2333</link>
      <description>&lt;P&gt;Asking the dev's we understand that this is not the default behavior and that something is clearly broken in the code.&lt;BR /&gt;
The workaround, till this gets fixed, would be not to use file uploading as a means to bring data to splunk if you care for field extractions. If you use regular monitoring stanza, both index-time field extractions as well as header-checking field extractions happen without any issues.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
.gz&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2010 01:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17063#M2333</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-07-09T01:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction do not work when using the UPLOAD method</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17064#M2334</link>
      <description>&lt;P&gt;Another workaround here is to continue to use file uploads, but manually configure the delimiter based extraction for the source or sourcetype. It should be noted that &lt;CODE&gt;CHECK_FOR_HEADER&lt;/CODE&gt; doesn't perform any magic beyond setting a per-sourcetype search-time field extraction rule. This is easy to achieve for a person after indexing the data. The documentation at &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Extractfieldsfromfileheadersatindextime" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Extractfieldsfromfileheadersatindextime&lt;/A&gt; shows the configuration that &lt;CODE&gt;CHECK_FOR_HEADER&lt;/CODE&gt; makes when a new input comes in.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2010 03:32:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17064#M2334</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2010-08-20T03:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction do not work when using the UPLOAD method</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17065#M2335</link>
      <description>&lt;P&gt;In many live environments, this is necessary anyway, as CHECK_FOR_HEADER doesn't work if files are collected by a forwarder and sent to an indexer, or if you have a distributed search head separate from your indexer or forwarder.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:16:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-Extraction-do-not-work-when-using-the-UPLOAD-method/m-p/17065#M2335</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2020-09-28T09:16:29Z</dc:date>
    </item>
  </channel>
</rss>

