Getting Data In

When indexing an Excel file with the .xlsx file extension, why is the format not showing properly in Splunk?

gyslainlatsa
Motivator

Hello everyone,

I have an Excel file to .xlsx format. When I load it in Splunk, it does not turn around the correct results.
Can someone help me?

Here's how the file is displayed in Excel:

alt text

and when I load it in Splunk, here's how it appears:

alt text

0 Karma

woodcock
Esteemed Legend

You need to pick a subset of the spreadsheet that is straight tabular data with no formulas, strip out everything else, "Save As CSV" and then it will work. The resulting file should have a set of fields separated by commas that is consistent from top to bottom with a field header as the top row. Your stuff is NOTHING like that.

0 Karma

loveforsplunk
Explorer

I think it is because you are not using CSV format. Just change the extension of the excel in .csv and splunk should be able to read the file.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Splunk doesnt support xls formatting as its a proprietary binary (Microsoft) format. If you want to load this in Splunk, save it as a CSV file and upload it into Splunk.

gyslainlatsa
Motivator

hi esix,
thank for your answer but I know, I read in a paper that splunk enterprise Splunk indexes all data types and why you say while splunk does not support the .xlsx extension?

0 Karma

woodcock
Esteemed Legend

All "plain-text" data.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Perhaps you can understand Splunk more by reading the documentation from Splunk as to what we can index :
http://docs.splunk.com/Documentation/Splunk/6.3.1/Data/WhatSplunkcanmonitor

Splunk cant read binary data without preprocessing or converting to human readable text.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...