<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263951#M79224</link>
    <description>&lt;P&gt;You did not mention &lt;CODE&gt;props.conf&lt;/CODE&gt; in your question so we had to guess.  That is why it is important to clearly spell out what you have done so far.  No, &lt;CODE&gt;max_match&lt;/CODE&gt; is not part of the &lt;CODE&gt;props.conf&lt;/CODE&gt; way of extracting fields.  I will post another answer.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2016 03:02:56 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2016-03-30T03:02:56Z</dc:date>
    <item>
      <title>Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263944#M79217</link>
      <description>&lt;P&gt;I'm trying to extract fields from a basic .csv log with no luck. &lt;/P&gt;

&lt;P&gt;Here is the file how it looks in Splunk 6.2.5.. &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1178iBE0D6A503965907C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;When I try to configure a field extraction, Splunk only recognizes the very first instance....&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1179iED9C9497FA5B7CAB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated - thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 18:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263944#M79217</guid>
      <dc:creator>dcascione</dc:creator>
      <dc:date>2016-03-29T18:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263945#M79218</link>
      <description>&lt;P&gt;I assume you are using &lt;CODE&gt;rex&lt;/CODE&gt; so you need to use the &lt;CODE&gt;max_match=0&lt;/CODE&gt; option.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 19:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263945#M79218</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-03-29T19:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263946#M79219</link>
      <description>&lt;P&gt;The data is being loaded into a single event.  &lt;/P&gt;

&lt;P&gt;Should it break thusly?&lt;BR /&gt;
3/29/2016,APC-DEV,-,0,0,0,0&lt;BR /&gt;
3/29/2016,MPC-TEMP,0,3,03&lt;/P&gt;

&lt;P&gt;If that's so, please let me know... &lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 19:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263946#M79219</guid>
      <dc:creator>cpraznowski_spl</dc:creator>
      <dc:date>2016-03-29T19:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263947#M79220</link>
      <description>&lt;P&gt;Yes, This is how I would like to see the log file break....&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 19:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263947#M79220</guid>
      <dc:creator>dcascione</dc:creator>
      <dc:date>2016-03-29T19:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263948#M79221</link>
      <description>&lt;P&gt;Should this option be added to the props.conf located here:  /opt/splunk/etc/deployment-apps/app_common/local    ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 19:40:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263948#M79221</guid>
      <dc:creator>dcascione</dc:creator>
      <dc:date>2016-03-29T19:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263949#M79222</link>
      <description>&lt;P&gt;got it....that's the problem, need to break after the carriage return.   &lt;/P&gt;

&lt;P&gt;1) When you ingest the file, you need to create a new custom sourcetype. &lt;BR /&gt;
2) in $splunk/etc/apps/search/local .... you'll see that new sourcetype referenced. &lt;BR /&gt;
3) you need to instruct splunk to break after each line: LINE_BREAKER = ([\r\n]+)&lt;/P&gt;

&lt;P&gt;...or the props.conf on the deployment server should work as well....&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Indexmulti-lineevents"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Indexmulti-lineevents&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 19:49:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263949#M79222</guid>
      <dc:creator>cpraznowski_spl</dc:creator>
      <dc:date>2016-03-29T19:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263950#M79223</link>
      <description>&lt;P&gt;When you go to production yes, tthe props.conf will then get sent to the forwarder that is collecting the data. &lt;/P&gt;

&lt;P&gt;But for now you can test in :  in $splunk/etc/apps/search/local .. and local the file a local directory to test...does that make sense?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 23:10:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263950#M79223</guid>
      <dc:creator>cpraznowski_spl</dc:creator>
      <dc:date>2016-03-29T23:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263951#M79224</link>
      <description>&lt;P&gt;You did not mention &lt;CODE&gt;props.conf&lt;/CODE&gt; in your question so we had to guess.  That is why it is important to clearly spell out what you have done so far.  No, &lt;CODE&gt;max_match&lt;/CODE&gt; is not part of the &lt;CODE&gt;props.conf&lt;/CODE&gt; way of extracting fields.  I will post another answer.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 03:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263951#M79224</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-03-30T03:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to extract all fields from a CSV log in Splunk 6.2.5?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263952#M79225</link>
      <description>&lt;P&gt;In &lt;CODE&gt;props.conf&lt;/CODE&gt; you need &lt;CODE&gt;KV_MODE=multi&lt;/CODE&gt;&lt;BR /&gt;
- Used for search-time field extractions only.&lt;BR /&gt;
- Specifies the field/value extraction mode for the data.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 03:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-unable-to-extract-all-fields-from-a-CSV-log-in-Splunk-6/m-p/263952#M79225</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-03-30T03:06:14Z</dc:date>
    </item>
  </channel>
</rss>

