Getting Data In

Importing CSV files with semi colon separated value.

jdelahaye35
New Member

Hello everybody.

I am working on data sources which are CSV files with semi-colon separated values.
Splunk seems to accept only CSV files with comma seprated value.
I have tried to create a data type under the "settings/data type menu" to add a structured source type with semicolon as field separator.

The problem is that I can't select the semicolon in the "field separator" dropdown.

Is anybody has found a solution to fix that issue?

Best regards

Tags (2)
0 Karma

herbie_53
Explorer

As this might be helpful for others still looking for a solution:
When adding data after selecting Source type: csv you should be able to to open the Advanced menu at the bottom.
There you can click on New Settings and add Name FIELD_DELIMITER with Value ;
After applying the settings it should work as desired (tested using Splunk 7.1.4).

Kind regards
Herbie

jdelahaye35
New Member

Hi thank you for your answer,

I have created a lookup file with the french version of Excel and have saved it as .CSV.
However, that version is using the semicolon character (;) as a separator instead of a comma, and splunk doesn't recognize that pattern.

So i thought Splunk could alIow me to create a data type (.csv) which recognize the patern with semi-colon separator (VALUE1;VALUE2...), but seems like it is not the case..

I have manually edited the lookup file.

Best regards

0 Karma

iamarkaprabha
Contributor

Hi ,

Only CSV files can be used for lookups. You will need to write a script to convert the file from semi-colon separated to CSV. Or perhaps use a manual tool to convert the file to CSV (for example, Microsoft Excel can import data with arbitrary delimiters).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...