Getting Data In

How to process a text file

TimothyPeh
Engager

Hi,

I have a test file which I want to process in Splunk. I'm able to load it into Splunk, but I'm trying to get Splunk to understand the fields and I'm stuck in what to do next.

For example:

Timestamp Event
1 10/14/13 10:43:35.000 AM

H20130326

2 10/14/13 10:43:35.000 AM

D HE12201303250329551124038092GTB27C02020402201303250337540000700000000000000

3 10/14/13 10:43:35.000 AM

D HE12201303250331431120034094GTB27C02020402201303250341580001000000000000000

4 10/14/13 10:43:35.000 AM

D HE12201303250349001050366450GTB27C02020402201303250350440000100000000000000

As you can see, my data is pretty much a long line of characters. In excel, I would use delimiter by field length to extract the data for excel to understand the file. Can I do the same thing with Splunk?

Much help is appreciated!

Thanks in advanced.

0 Karma

Lucas_K
Motivator

Have you tried using the Data input's data preview in the splunk web gui?

Click manager/data/data inputs/Add data.

It will allow you to play with the field extractions until its looking right.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...