Getting Data In

Blank Values being filled with data

vishalduttauk
Path Finder

Hi all,

I am uploading a csv which has two columns, Status and Flag. I am having issues where the Flag field is being populated with the value which is set in the status field even when flag is blank.

i.e. If status is O and Flag is blank then Flag is being populated with O as well.

 

Can you help?

Labels (2)
Tags (3)
0 Karma
1 Solution

vishalduttauk
Path Finder

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

View solution in original post

0 Karma

vishalduttauk
Path Finder

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share your current configuration which is not working as you expect?

0 Karma

vishalduttauk
Path Finder

Sorry I am fairly new to Splunk. What configuration information do you need?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

transforms and props configurations for ingesting the csv file? or do you ingest the file another way?

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...