Getting Data In

How to import more than 50 fields with CSV in Splunk 6?

swilhoi2
New Member

We are having a problem with importing all of our data fields because we are only getting the first 50 fields using version 6.

If someone could help me out with this I would greatly appreciate it.

Thank you,
Seth Wilhoite

Tags (1)
0 Karma

guilmxm
Influencer

Hi,

This is a kv limit in default Splunk configuration.

Edit your $SPLUNK_HOME/etc/system/local/limits.conf and set: (see your default/limits.conf for the full section)

[kv]
# maximum number of keys auto kv can generate
limit    = 50

To a value that would feet your need.

Restart Splunk and re-index your data.

I had the same issue, took me some time to understand and find that 🙂

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...