Ignoring the obvious question (Why?), you can set up transforms.conf with DELIMS
and FIELDS
to parse 1,2,3
into three named fields at search time on the indexers according to the search head's knowledge bundle.
Ignoring the obvious question (Why?), you can set up transforms.conf with DELIMS
and FIELDS
to parse 1,2,3
into three named fields at search time on the indexers according to the search head's knowledge bundle.
Very kind @martin_mueller - thank you!
And from our Sales Engineer - CSVs are nice because they’re so simple. There are commas delimiting fields and a field header.
Example config - Extract fields from files with structured data