Getting Data In

Blank Values being filled with data

vishalduttauk
Communicator

Hi all,

I am uploading a csv which has two columns, Status and Flag. I am having issues where the Flag field is being populated with the value which is set in the status field even when flag is blank.

i.e. If status is O and Flag is blank then Flag is being populated with O as well.

 

Can you help?

Labels (2)
Tags (3)
0 Karma
1 Solution

vishalduttauk
Communicator

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

View solution in original post

0 Karma

vishalduttauk
Communicator

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share your current configuration which is not working as you expect?

0 Karma

vishalduttauk
Communicator

Sorry I am fairly new to Splunk. What configuration information do you need?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

transforms and props configurations for ingesting the csv file? or do you ingest the file another way?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...