I am monitoring a folder with csv files with 400+ fields, out of which need only 50 fields for my dashboard.
Can we do something in Indexing time, so that it will not index the other 350 fields which are not required.
Removing from CSV is not possible. So, need to handle it in splunk only.
You can do this with a carefully constructed
SEDCMD setting but this may not work if you are using
INDEXED_EXTRACTIONS=csv (then again, it may very well work). I know that it definitely will work if you are not using
I don't know if it's working for 400+ fields but I found this post for you : https://answers.splunk.com/answers/529138/filter-csv-logs-before-indexing.html
Ok, I will try this
Let me know if it works