Getting Data In

Populate header as field in each row in CSV file

surendrarhi
New Member

Hi,

I want to index a csv file, the data looks like

"ID","Name","hiredate"
"1","John","01-12-2014"
"2","Bob","01-12-2014"
"3","Mary","01-12-2014"

When the data is indexed i want to see the data like:

ID=1,Name=John,hiredate=01-12-2014
ID=2,Name=Bob,hiredate=01-12-2014
ID=3,Name=Mary,hiredate=01-12-2014

Is there a way to this, currntly the data in index looks like

1,John,01-12-2014

2,Bob,01-12-2014

3,Mary,01-12-2014

Thanks

Tags (3)
0 Karma
1 Solution

ogdin
Splunk Employee
Splunk Employee

No but I assume you want the "=" in the event to make search-time auto key-value extraction work. Use this instead:

http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime

Put this in props.conf

INDEXED_EXTRACTIONS=CSV

Then in the Splunk Search field picker you will see:

alt text

And you can show the fields in the events if you want:

alt text

View solution in original post

ogdin
Splunk Employee
Splunk Employee

No but I assume you want the "=" in the event to make search-time auto key-value extraction work. Use this instead:

http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime

Put this in props.conf

INDEXED_EXTRACTIONS=CSV

Then in the Splunk Search field picker you will see:

alt text

And you can show the fields in the events if you want:

alt text

Get Updates on the Splunk Community!

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...