I have the following configurations deployed on the Universal Forwarder. However Splunk is incorrectly treating the first row of the file as the CSV header and using those values as field names. Instead, I want the events parsed as headerless CSV data, with the field names defined explicitly in the FIELDS parameter of the corresponding transforms.conf stanza.
> cat inputs.conf
[monitor:///<path>]
index = main
sourcetype = xxx:test
> cat props.conf
[xxx:test]
SHOULD_LINEMERGE = false
INDEXED_EXTRACTIONS = csv
REPORT-fields = assign_csv_fields
> cat transforms.conf
[assign_csv_fields]
FIELDS = AccountNumber, Amount, Origin, TransactionCode, TransactionDate, TransactionTime,
UNIQUEID, Counter, OFFSETACT, Filler
OK. Where are which settings defined?
With indexed extractions you have an option to define a header line (and I'm not sure if it's not defined by default).
If you want to explicitly provide a list of fields, it's probably better to _not_ use indexed extractions but use FIELD_DELIMITER and parse in search time.
OK. Where are which settings defined?
With indexed extractions you have an option to define a header line (and I'm not sure if it's not defined by default).
If you want to explicitly provide a list of fields, it's probably better to _not_ use indexed extractions but use FIELD_DELIMITER and parse in search time.
Thank you @PickleRick !!
The following did it -
INDEXED_EXTRACTIONS = csv
FIELD_NAMES=SQLFIELD,Field1,Field2,Field3,Field4,Field5,Field6,Field7,Field8,Field9