All Apps and Add-ons

Splunk can't read csv updated by lookup file editor

keymountain
Explorer

Splunk cannot read csv updated by lookupeditor correctly.

For example, in the following cases, Splunk cannot read correctly.
1. Pressed the Save button without changing the contents
2. Added a row at the bottom of csv file

However, Splunk can be read correctly in the following cases.
1. Pressed the Save button with changing the contents
2. Added a row between rows of csv file

Does anyone have a similar problem?
Any help will be greatly appreciated.

Regards,
Kagiyama

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What error message(s) do you get?
Have you tried a different version of Lookup File Editor?

---
If this reply helps you, Karma would be appreciated.
0 Karma

keymountain
Explorer

Thank you for your response.

I checked the index(internal or audit) and found no errors.
It does not occur in different versions of Lookup File Editor or different environments.

The following is a file generation image.
In all cases the contents of all files are correct.

-rw------- 1 splunk splunk 326 10:20 xxx.csv

-rw------- 1 splunk splunk 284 10:10

Press the Save at 10:30

-rw------- 1 splunk splunk 326 10:30 xxx.csv

-rw------- 1 splunk splunk 284 10:10
-rw------- 1 splunk splunk 284 10:20

However, splunk may not be able to read these files correctly when importing them.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Which version of splunk?

0 Karma

keymountain
Explorer

Version is 7.1.2 .

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...