I have uploaded a csv file through the Splunk Web which has 157 columns and 4000 events.
I noticed that while directing to the index only 105 columns are visible with 4000 events.
Is there any limitation in splunk? And this is not the first time too I noticed this. Kindly help.
CSV files should be uploaded as
lookup files, not
event data. I am not sure what happened when you indexed this file, but try using it as
lookup file instead and they try
|inputlookup YourLookupFileName.csv and see if it works better (it probably will).
Thanks @woodcock. But this do not give a clarity why the columns are truncated.
I ingest csv file from the AWS S3 into splunk always.
These feeds do not qualify to be a Lookup.
Please help to understand why the truncation of columns.
|inputlookup your_AWS_S3.csv |head 1 |transpose
index=your_index |head 1 |transpose
When compared, there may be characters that cannot be used in field names.