All Apps and Add-ons

Splunk can't read csv updated by lookup file editor

keymountain
Explorer

Splunk cannot read csv updated by lookupeditor correctly.

For example, in the following cases, Splunk cannot read correctly.
1. Pressed the Save button without changing the contents
2. Added a row at the bottom of csv file

However, Splunk can be read correctly in the following cases.
1. Pressed the Save button with changing the contents
2. Added a row between rows of csv file

Does anyone have a similar problem?
Any help will be greatly appreciated.

Regards,
Kagiyama

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What error message(s) do you get?
Have you tried a different version of Lookup File Editor?

---
If this reply helps you, Karma would be appreciated.
0 Karma

keymountain
Explorer

Thank you for your response.

I checked the index(internal or audit) and found no errors.
It does not occur in different versions of Lookup File Editor or different environments.

The following is a file generation image.
In all cases the contents of all files are correct.

-rw------- 1 splunk splunk 326 10:20 xxx.csv

-rw------- 1 splunk splunk 284 10:10

Press the Save at 10:30

-rw------- 1 splunk splunk 326 10:30 xxx.csv

-rw------- 1 splunk splunk 284 10:10
-rw------- 1 splunk splunk 284 10:20

However, splunk may not be able to read these files correctly when importing them.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Which version of splunk?

0 Karma

keymountain
Explorer

Version is 7.1.2 .

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...