Getting Data In

Monitored CSV where the headers and number of columns are determined by one of the fields.

nikorc
Loves-to-Learn Lots

I need to monitor a csv file where the first 6 column headers are static but based on the 3rd column (a number 0-5) the next number of columns are dynamic as are their headers. I trying to understand how to configure the .conf files to have a dynamic set of headers based on the value of a column in the csv when sending to splunk.

Tags (2)
0 Karma

jkat54
SplunkTrust
SplunkTrust

In props.conf you have this option:

HEADER_FIELD_LINE_NUMBER = <integer>
* The line number of the line within the specified file or source that
  contains the header fields.
* If set to 0, Splunk software attempts to
  locate the header fields within the file automatically.
* Default: 0

Does it work?

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...