Hi,
I want to index a csv file, the data looks like
"ID","Name","hiredate"
"1","John","01-12-2014"
"2","Bob","01-12-2014"
"3","Mary","01-12-2014"
When the data is indexed i want to see the data like:
ID=1,Name=John,hiredate=01-12-2014
ID=2,Name=Bob,hiredate=01-12-2014
ID=3,Name=Mary,hiredate=01-12-2014
Is there a way to this, currntly the data in index looks like
1,John,01-12-2014
2,Bob,01-12-2014
3,Mary,01-12-2014
Thanks
No but I assume you want the "=" in the event to make search-time auto key-value extraction work. Use this instead:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime
Put this in props.conf
INDEXED_EXTRACTIONS=CSV
Then in the Splunk Search field picker you will see:
And you can show the fields in the events if you want:
No but I assume you want the "=" in the event to make search-time auto key-value extraction work. Use this instead:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime
Put this in props.conf
INDEXED_EXTRACTIONS=CSV
Then in the Splunk Search field picker you will see:
And you can show the fields in the events if you want: