Getting Data In

How to Read a CSV file (with time-stamped data for past 24 hours) and Index the data

Path Finder

Hello All,
My client's machine generates a daily data log (in csv format). How do one configure splunk to read & index the past 1 day of data. The csv file has the following format.
Header >> Datetime, Tag1, Tag2
Row1 >> 2017-07-01 23:00:00, 23.45, 12.56
Row2 >> 2017-07-01 23:01:00, 33.45, 22.56

Pls. advise. Thanks

Tags (2)


Please see below,

create $SPLUNK_HOME/etc/apps/yourapp/local/inputs.conf


$SPLUNK_HOME/etc/apps/your app/local/props.conf
REPORT-mysource = mysource_csv

DELIMS = ","
FIELDS = "field1","field2","field3","field4","field5".....

Go through below link for further details,

Path Finder

Thanks very much

0 Karma

Esteemed Legend

If you got it working, do click Accept to close your question.

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...