Getting Data In

Importing CSV files with semi colon separated value.

jdelahaye35
New Member

Hello everybody.

I am working on data sources which are CSV files with semi-colon separated values.
Splunk seems to accept only CSV files with comma seprated value.
I have tried to create a data type under the "settings/data type menu" to add a structured source type with semicolon as field separator.

The problem is that I can't select the semicolon in the "field separator" dropdown.

Is anybody has found a solution to fix that issue?

Best regards

Tags (2)
0 Karma

herbie_53
Explorer

As this might be helpful for others still looking for a solution:
When adding data after selecting Source type: csv you should be able to to open the Advanced menu at the bottom.
There you can click on New Settings and add Name FIELD_DELIMITER with Value ;
After applying the settings it should work as desired (tested using Splunk 7.1.4).

Kind regards
Herbie

jdelahaye35
New Member

Hi thank you for your answer,

I have created a lookup file with the french version of Excel and have saved it as .CSV.
However, that version is using the semicolon character (;) as a separator instead of a comma, and splunk doesn't recognize that pattern.

So i thought Splunk could alIow me to create a data type (.csv) which recognize the patern with semi-colon separator (VALUE1;VALUE2...), but seems like it is not the case..

I have manually edited the lookup file.

Best regards

0 Karma

iamarkaprabha
Contributor

Hi ,

Only CSV files can be used for lookups. You will need to write a script to convert the file from semi-colon separated to CSV. Or perhaps use a manual tool to convert the file to CSV (for example, Microsoft Excel can import data with arbitrary delimiters).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...