Hi all,
I am uploading a csv which has two columns, Status and Flag. I am having issues where the Flag field is being populated with the value which is set in the status field even when flag is blank.
i.e. If status is O and Flag is blank then Flag is being populated with O as well.
Can you help?
I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.
I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.
Can you share your current configuration which is not working as you expect?
Sorry I am fairly new to Splunk. What configuration information do you need?
transforms and props configurations for ingesting the csv file? or do you ingest the file another way?