Getting Data In

Ignore first line

aleem
SplunkTrust
SplunkTrust

Hi,
I am importing custom CSV files. The heading are are the first line. What is the simplest way to ignore these headings? Which files to I need to edit?

Be the best version of you
Tags (1)
0 Karma

lguinn2
Legend

Take a look at this question, which is quite close to yours.

How to ignore the title line of the csv file in the result and display in a kv format

I don't think that the CHECK_FOR_HEADER = true suggestion will work, but the solution that uses a TRANSFORM will.

0 Karma

lguinn2
Legend

If you tell Splunk that the sourcetype of the file is "csv", I believe Splunk will take care of that for you, as well as extracting the fields.

0 Karma

aleem
SplunkTrust
SplunkTrust

Thanks, I tried that. Splunk recognises sourcetype as csv-2 and still indexes the headings

Be the best version of you
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...