Getting Data In

Blank Values being filled with data

vishalduttauk
Communicator

Hi all,

I am uploading a csv which has two columns, Status and Flag. I am having issues where the Flag field is being populated with the value which is set in the status field even when flag is blank.

i.e. If status is O and Flag is blank then Flag is being populated with O as well.

 

Can you help?

Labels (2)
Tags (3)
0 Karma
1 Solution

vishalduttauk
Communicator

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

View solution in original post

0 Karma

vishalduttauk
Communicator

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share your current configuration which is not working as you expect?

0 Karma

vishalduttauk
Communicator

Sorry I am fairly new to Splunk. What configuration information do you need?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

transforms and props configurations for ingesting the csv file? or do you ingest the file another way?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Improve Delivery Assurance with S2S ACK for Edge Processor

Edge Processor helps Splunk customers process data closer to the source: filtering, transforming, masking, and ...

.conf26 Platform Sessions: Turn Machine Data into Agentic Action

As autonomous agents and multi-cloud architectures reshape modern IT, data platforms have to do far more than ...

Introducing the Launch of Edge Processor in Hybrid Mode!

Modernize Data Ingestion Without Starting Over  For years, organizations have relied on Splunk's proven ...