Getting Data In

Fields are missing from some of my records after importing a CSV file

ianthebrave
New Member

Hi!

I imported a CSV file with 97 fields and after doing some searches, some fields are missing for some records. I have this so-called 'close_notes' field and it's present to some of the records while there are a few records where it does not exist.

Thank you.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ianthebrave, if cusello answered your question please remember to accept the answer to both close this question and to award karma points. Happy splunking! 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

Sukisen1981
Champion

I second Giuseppe, look closely at your CSV and splunk events, your events will be separated by a , in the splunk events, it is possible that the data input field from your CSV is having some issues. There is no way that once uploaded, the splunk index misses some while accepting some close_notes field values. Have you checked if the fields in CSV BEFORE this field in your CSV is not blank / empty for some rows in the CSV?

0 Karma

gcusello
SplunkTrust
SplunkTrust

If this answer satisfies your question, please accept or upvote it.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...