Getting Data In

Blank Values being filled with data

vishalduttauk
Path Finder

Hi all,

I am uploading a csv which has two columns, Status and Flag. I am having issues where the Flag field is being populated with the value which is set in the status field even when flag is blank.

i.e. If status is O and Flag is blank then Flag is being populated with O as well.

 

Can you help?

Labels (2)
Tags (3)
0 Karma
1 Solution

vishalduttauk
Path Finder

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

View solution in original post

0 Karma

vishalduttauk
Path Finder

I found out the issue. The sourcetype was associated with a field which had been created previously. I removed the sourcetype which was a test and created a new one which resolved the issue.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share your current configuration which is not working as you expect?

0 Karma

vishalduttauk
Path Finder

Sorry I am fairly new to Splunk. What configuration information do you need?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

transforms and props configurations for ingesting the csv file? or do you ingest the file another way?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...