Getting Data In

Eventgen failing to parse csv- What am I doing wrong?

hhart
Splunk Employee
Splunk Employee

I have enabled eventgen and its does generate but I keep hitting the same issue when it tries to pass a sample log with "" 

 

time="2023-06-08T23:02:21Z" level=info msg="Parsing configuration for sample: ActiveDirectoryLab.sample"
time="2023-06-08T23:02:21Z" level=info msg="Parsing configuration for sample: apache_access_demo.csv"
time="2023-06-08T23:02:21Z" level=fatal msg="Failed to read csv sample file: parse error on line 2, column 40: bare \" in non-quoted-field"

 

Any suggestions on what I am doing wrong would be appreciated

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...