Indexing gz tar csv files

New Member

I have a gz file that has tar file inside ( unfortunately without .tar extension though ), finally tar contains csv file
What would be a correct way to make Splunk to index that csv?
Splunk indeed opens gz file but here I have several levels of nesting ....
I also noticed that when Splunk is instructed to read a folder containing csv files, it ignores csv header that each csv has and then field can't be referenced by name, is there a way to avoid it?
Thank you

Hey ngm,

You can add this parameter to your props.conf to check header
HEADER_FIELD_LINE_NUMBER = 1 (to specify the line number of the header)

You can refer this link:

Let me know if this helps!!

