What are some of the methods that I can remove the header row after running the 'outputcsv' command in my search?
Here are some of the fields in that header row:
CreateTimeStamp_GMT Data_Source Reference_Number SourceIP_Address Incident_Category
Option 1 is documented here: http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Routeandfilterdatad#Filter_event_data_and_sen...
Option 2 is documented here:http://docs.splunk.com/Documentation/Splunk/4.3/Data/Anonymizedatausingconfigurationfiles#Through_a_...
Oh sorry I notice that this is after using outputcsv! No you cannot do it.
Pretty sure that there is no way to do this when the outputcsv command is called to generate the csv file with events from your search results. I would recommend using a script to clean up the CSV file after its been generated for which SED would be useful or using batch/cmd/powershell on Win systems.
Option 1 is documented here: http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Routeandfilterdatad#Filter_event_data_and_sen...
Option 2 is documented here:http://docs.splunk.com/Documentation/Splunk/4.3/Data/Anonymizedatausingconfigurationfiles#Through_a_...
Oh sorry I notice that this is after using outputcsv! No you cannot do it.