Getting Data In

CSV inconsistent field value

lloydknight
Builder

Hello Splunkers,

So I have this csv file that a certain field contains 10+ numbers.
Please see sample image below:

alt text

Tried changing its format from General to Text in csv before indexing it but I still get this scientific numbers.

Thoughts?

Thanks!

Tags (1)
0 Karma
1 Solution

sduff_splunk
Splunk Employee
Splunk Employee

Can you confirm in the source file that it is using exponential notation? You can check by using the "Show Source" Event Action, or look at the original event.

I expect that the original file will have both decimal and exponential notation, which is causing this.

View solution in original post

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Can you confirm in the source file that it is using exponential notation? You can check by using the "Show Source" Event Action, or look at the original event.

I expect that the original file will have both decimal and exponential notation, which is causing this.

0 Karma

lloydknight
Builder

Hello sduff, this was solved by not opening the downloaded csv and indexed it directly on Splunk. Not sure what's the explanation for this though. Thanks.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

The problem was likely that your editor (Excel?) converted some of the values in the CSV into scientific notation. As you said, going directly into Splunk didn't have that issue.

lloydknight
Builder

yes most likely my MS Excel converted some of the values into scientific notation.

0 Karma

woodcock
Esteemed Legend

You should click Accept to close this question.

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...