Getting Data In

CSV file not uploaded to splunk

thinman
Explorer

Hi,

I have a little problem with a cvs file, this is the example:

"Cuenta Facturable","N° Facturable","N° Origen","Localidad o País Origen","Carrier","N° Destino","Destino","Fecha","Hora inicio","Tiempo Facturable","Unidad Facturable","Tarifa","Importe","Tipo de llamada"
"40057561","22111471","22111471","LA PAZ","00","72023079","LA PAZ","2011-03-11","11:49:50","19","SEG","       0.02667","       0.50673","14.2"

When loaded to splunk> only headers are recognized but no the data line.

Thanks for your time

Julio

Tags (2)
0 Karma

RicoSuave
Builder

How are you uploading the file? I remember having the same issue and it was solved when i told splunk that the sourcetype was a csv. When in the process to upload the file, make sure you check the "More settings" box then go to sourcetype and select "From List" then select csv. This should fix the problem that you are having. Let me know if this works.

thinman
Explorer

Sorry, I´ve found what happend. splunk> has found the date!! and added the event to te date and not when the file was uploaded!!!!

Thanks for your time

0 Karma

thinman
Explorer

No, no luck. Do you know where to look for the log of the uploaded file? to get mor information on the upload process.

Thanks

0 Karma

thinman
Explorer

Yes, I've selected cvs (cvs-12 y cvs-13) with no luck. Let my try again.

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...