we have records with multiline fields.
If you do an CSV-export, MS Excel struggles as the export is really comma-separated.
Excel can only handle semicolon- or tab-separated values.
The Splunk Python Modules are already capable to do "Excel-CSV".
How and where can we tell Splunk to export "Excel-CSV"?
I may not be taking the same path you are, but when I "Export results" from search in the UI and save it as CSV, Excel 2007 doesn't have any problem opening the file even though the _raw data I have is multiline.
When I try to run the CSV file through the text import wizard, it doesn't handle the multiline fields well. It treats every newline in the file as a new row in the Excel file. What I found was the only way to get multiline CSV values into Excel was to open the file directly into Excel. Text import didn't handle the multiline fields for me.
we're using Office 2003 and Splunk 4.1.7
The search is like:
a and b are multiline.
When opening it directly in excel, for each newline in the field a new row is created in excel.
Actually Excel can handle just about any delimiter if you use the "Text import Wizard". I use this feature quite often. This link might help :
Then you might need to look at how the events are being indexed. It's possible the event boundaries are not correct. Just a guess, without seeing your data, you might have to edit the props.conf for this sourcetype to correct line breaking on multi-line events. http://www.splunk.com/base/Documentation/4.2.1/Data/Indexmulti-lineevents
thanks for the quick answer.
This would work, if the fields were not multiline.
The main reason is the inconvenience for the user.
Goal is that the export can directly opened in MS Excel.