I am trying to load this CSV file:
time,name,ActiveUsers,CaptureTimeDelta,CurrentValue,DeltaTimeAuditLog,Kurtosis,LocalTimeDelta,Mean,Samples,Skew,Variance 2019-02-12T13:10:36,AddShipments,,,0.00000000,,88.10602295,,0.00970874,103,9.16633183,0.00961448 2019-02-12T13:10:36,ConsolCount,,,1.00000000,,3.67393608,,1.48936170,94,1.23317451,0.65414215 2019-02-12T13:10:36,EditConsols,,,0.00000000,,0.00000000,,0.00000000,94,0.00000000,0.00000000 2019-02-12T13:10:36,EditShipments,,,0.00000000,,38.53877106,,0.02127660,94,6.19019906,0.02082390 2019-02-12T13:10:36,GetAuditWindow,,,5.00000000,,210.03408186,,26.39361702,94,3.16661255,12504.23868266 2019-02-12T13:10:36,GetConsols,,,0.00000000,,68.64629382,,1.60638298,94,8.01521793,63.49400181 2019-02-12T13:10:36,GetShipments,,,4.00000000,,4.62276245,,50.74468085,94,1.55334745,2470.61566320 2019-02-12T13:10:31,MQFlushStandardQueue,,,0.00000000,,39.47942421,,0.02127660,94,6.32050599,0.02082390 2019-02-12T13:10:31,MQFlushStatsQueue,,,0.00000000,,0.00000000,,0.00000000,94,0.00000000,0.00000000 2019-02-12T13:10:31,MainLoop,,,92.00000000,,72.99251268,,79.29787234,94,2.95450406,15798.86871888 2019-02-12T13:10:36,PageFaultCount,,,77049.00000000,,,,,,, 2019-02-12T13:10:36,PagefileUsage,,,64151552.00000000,,,,,,, 2019-02-12T13:10:36,PeakPagefileUsage,,,108593152.00000000,,,,,,, 2019-02-12T13:10:36,PeakWorkingSetSize,,,101318656.00000000,,,,,,, 2019-02-12T13:10:36,QuotaNonPagedPoolUsag,,,24736.00000000,,,,,,, 2019-02-12T13:10:36,QuotaPagedPoolUsage,,,162840.00000000,,,,,,, 2019-02-12T13:10:36,QuotaPeakNonPagedPoolUsage,,,1080064.00000000,,,,,,, 2019-02-12T13:10:36,QuotaPeakPagedPoolUsage,,,162840.00000000,,,,,,, 2019-02-12T13:10:36,ShipmentCount,,,1.00000000,,3.67393608,,1.48936170,94,1.23317451,0.65414215 2019-02-12T13:10:36,WorkingSetSize,,,69599232.00000000,,,,,,, 2019-02-12T13:10:36.02,StatsMonitor,2065,0.36,,0.56,,0,,,,
I am using Splunk Free to develop some dashboards and processes, so everything is local. I have tried simply loading it interactively or via directory scan. The end result is the same.
When I load it interactively, the process in Splunk Web displays the heading, which is in the first line. Everything looks right at this stage. However, when the loading process is complete, there seems to be no knowledge of the headings in the search tool. The timestamp is picked up correctly, but the meaning of each column seems to be lost. I am using the default csv source type. I have tried variations of this sourfce type with no success (specifying the heading line etc).
What am I missing here?