Getting Data In

Blank Values being filled with data

vishalduttauk
Communicator

Hi all,

I am uploading a csv which has two columns, Status and Flag. I am having issues where the Flag field is being populated with the value which is set in the status field even when flag is blank.

i.e. If status is O and Flag is blank then Flag is being populated with O as well.

 

Can you help?

Labels (2)
Tags (3)
0 Karma
1 Solution

vishalduttauk
Communicator

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

View solution in original post

0 Karma

vishalduttauk
Communicator

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share your current configuration which is not working as you expect?

0 Karma

vishalduttauk
Communicator

Sorry I am fairly new to Splunk. What configuration information do you need?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

transforms and props configurations for ingesting the csv file? or do you ingest the file another way?

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...