Getting Data In

Multiple lines in CSV are in one event, how to separate it?

Durga
Engager

Hello respective,

    i have a CSV type file which contains multiple lines of data. when i upload into the splunk few line of data merged into a single event. i try to put few blank lines in between those lines, but still the lines are in a single event. 

Ex. (csv file data)

First line in csv, first row, first word

Second line in csv, second row, second word

Third line in csv, third row, third word.

the above data i upload into splunk, then second and third line should one each single event, but it's coming in one event. 

then i update the file.

Ex. (csv file data updated extra line in between lines)

First line in csv, first row, first word

 

Second line in csv, second row, second word

 

Third line in csv, third row, third word.

but still the result is same. it's not making 3 events, it's merging 2 lines to one event. 

 

Labels (6)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are the props.conf settings for that sourcetype?

---
If this reply helps you, Karma would be appreciated.

Durga
Engager

i am not sure, because it's done by the ADMIN's and i am only the user. can you please explain bit what need to be fixed in the .conf for this issue.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's impossible to say what needs to be fixed without seeing what is there now.  Please work with your admins.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...