Getting Data In

Is it possible to upload a csv file into Splunk without adding it onto the physical splunk server?

splunkman341
Communicator

Hi guys,

I've roamed the prestigious documents of splunk on how to go about this but I am stumped and can't find any guidance. Just as the question states, I am trying to upload a csv file into splunk, without having to go on the physical splunk server and moving it in. Is this possible?

Thanks in advance for your help

Labels (1)
Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

This is a common problem when converting an Excel file to CSV. Try saving it as Windows Comma Separated Value (.csv), then you should be able to successfully upload the lookup.

View solution in original post

woodcock
Esteemed Legend

This is a common problem when converting an Excel file to CSV. Try saving it as Windows Comma Separated Value (.csv), then you should be able to successfully upload the lookup.

LukeMurphey
Champion

Try using the Lookup Editor app. It provides an interface for uploading lookup files and it will even correct incompatible line endings.

To upload a file, do the following:

  1. Open the Lookup Editor
  2. Click "New"
  3. Click the file selector at the top right of the screen near where it says "Import from CSV file"; once your file it uploaded it will appear in the interface
  4. Set a name for the lookup and press save

lquinn
Contributor

Can you access the Splunk UI from the server where the file is? Then you could just go to Settings > Add Data, then drag and drop the file.

0 Karma

splunkman341
Communicator

Thanks for your response.

So i went to Settings > look ups > look up table files and when I tried to add my csv file I get an error message saying : Encountered the following error while trying to save: In handler 'lookup-table-files': File has no line endings.

Any idea on how to successfully upload it?

0 Karma

splunker12er
Motivator

There might be some problem in the file, which you are trying to upload, this is a common problem when converting an Excel file to CSV.

Try saving it as Windows Comma Separated Value (.csv), then you should be able to successfully upload the lookup.

gcarson_splunk
Splunk Employee
Splunk Employee

There are also some edge cases where if the csv column names have more than 4094 bytes characters Splunk will throw this error.

The solution in my case was to pre-process the csv and truncate the column names.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...