Getting Data In

Selectively ignoring fields in CSV input?

msarro
Builder

Hey everyone. I am trying to input .csv files. The issue with the files is that the software generating them includes the timestamp numerous times in each line. Here's a rough example:

timestamp,CPU Usage, timestamp, Memory usage, timestamp, temperature, timestamp, license usage, timestamp, SNMP reachability

You get the idea. I don't want to waste space indexing all of the extra timestamp fields. Any advice?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can use an index time TRANSFORM, or more likely a SEDCMD to modify the data before it goes into the index: http://www.splunk.com/base/Documentation/4.1.6/Admin/Anonymizedatawithsed

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...